check-npm
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed as a read-only audit tool, with instructions explicitly stating, 'Do not modify any files.'
- [SAFE]: All operations utilize standard, non-destructive shell commands such as
jq,grep,find, andlsto verify configuration values inpackage.json,.npmrc, and other manifest files. - [SAFE]: The skill references trusted external resources, specifically official Grafana GitHub repositories and documentation from Yarn, which are consistent with the identified author and tool purpose.
- [SAFE]: Fix suggestions provided in the documentation are intended for manual user application and are not executed automatically by the agent.
- [SAFE]: No evidence of prompt injection, data exfiltration, obfuscation, or unauthorized privilege escalation was found.
Audit Metadata