package-plugin

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes node scripts/package-plugin.mjs to build plugin archives. This operation targets local scripts included in the repository distribution as part of a development workflow.\n- [SAFE]: The packaging logic incorporates several validation gates, including checks for symlinks, OS-specific hidden files (e.g., .DS_Store), and manifest integrity via release-manifest.json SHA256 verification.\n- [SAFE]: All external references, such as the marketplace installation command for nexu-io/open-design-agent-plugins, are consistent with the identified vendor and the skill's primary purpose of plugin distribution management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 02:18 AM
Security Audit — agent-trust-hub — package-plugin