npm-workflow-discipline

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard guidance for using npm commands such as npm ci and npm install for reproducible workflows and lockfile discipline.
  • [PROMPT_INJECTION]: The identified 'ignore previous instructions' string in references/evals.yaml is part of a security test suite used to evaluate the agent's resistance to adversarial prompts, not a malicious instruction.
  • [DATA_EXFILTRATION]: The instructions include a clear constraint to redact secrets, tokens, and credentials from outputs, which is a significant security control to prevent data exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 01:13 PM
Security Audit — agent-trust-hub — npm-workflow-discipline