package-plugin
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes
node scripts/package-plugin.mjsto build plugin archives. This operation targets local scripts included in the repository distribution as part of a development workflow.\n- [SAFE]: The packaging logic incorporates several validation gates, including checks for symlinks, OS-specific hidden files (e.g.,.DS_Store), and manifest integrity viarelease-manifest.jsonSHA256 verification.\n- [SAFE]: All external references, such as the marketplace installation command fornexu-io/open-design-agent-plugins, are consistent with the identified vendor and the skill's primary purpose of plugin distribution management.
Audit Metadata