npm-workflow-discipline
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard guidance for using npm commands such as
npm ciandnpm installfor reproducible workflows and lockfile discipline. - [PROMPT_INJECTION]: The identified 'ignore previous instructions' string in
references/evals.yamlis part of a security test suite used to evaluate the agent's resistance to adversarial prompts, not a malicious instruction. - [DATA_EXFILTRATION]: The instructions include a clear constraint to redact secrets, tokens, and credentials from outputs, which is a significant security control to prevent data exposure.
Audit Metadata