npm-package

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard best practices for JavaScript package development, including ESM/CJS dual-module configuration and monorepo management with pnpm.
  • [SAFE]: All referenced tools (e.g., tsup, unbuild, publint, arethetypeswrong, @changesets/cli) are legitimate, widely-used utilities within the JavaScript ecosystem.
  • [SAFE]: Sensitive data management, such as handling npm tokens, correctly instructs the use of environment variables and CI secrets instead of hardcoding credentials.
  • [SAFE]: The CI/CD workflows provided for GitHub Actions use standard security patterns and do not contain malicious instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 03:40 PM
Security Audit — agent-trust-hub — npm-package