npm-package
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard best practices for JavaScript package development, including ESM/CJS dual-module configuration and monorepo management with pnpm.
- [SAFE]: All referenced tools (e.g.,
tsup,unbuild,publint,arethetypeswrong,@changesets/cli) are legitimate, widely-used utilities within the JavaScript ecosystem. - [SAFE]: Sensitive data management, such as handling npm tokens, correctly instructs the use of environment variables and CI secrets instead of hardcoding credentials.
- [SAFE]: The CI/CD workflows provided for GitHub Actions use standard security patterns and do not contain malicious instructions.
Audit Metadata