package-publishing

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of educational documentation and configuration templates for standard npm package management. The instructions follow industry best practices, such as recommending the use of --provenance for supply chain security and explicitly advising users to check for secrets before publishing.
  • [EXTERNAL_DOWNLOADS]: The skill references official GitHub Actions (actions/checkout, actions/setup-node) and well-known, community-standard development tools (tsup, unbuild, rollup, publint, @arethetypeswrong/cli). These references are legitimate and do not involve untrusted or suspicious sources.
  • [COMMAND_EXECUTION]: The skill includes instructions for standard development commands, such as npm pack, npm publish, and npm version. These are standard tools for the package-authoring domain and are used in a transparent, safe manner.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:50 AM
Security Audit — agent-trust-hub — package-publishing