plugin-release

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions involve cloning the vendor's official repository from GitHub (deepseek-ai/deepseek-harness) to facilitate artifact validation and packaging.
  • [COMMAND_EXECUTION]: Provides instructions for using standard development tools including npm, pnpm, and git, as well as the vendor-specific dsh CLI. The skill includes a clear safety boundary requiring user confirmation before any publishing or tagging actions.
  • [DATA_EXFILTRATION]: Network operations are limited to interaction with the official npm registry and the project's own GitHub repositories for legitimate release management purposes.
  • [SAFE]: No indicators of prompt injection, obfuscation, or malicious code execution were found. The skill includes explicit best-practice warnings against including credentials or private configuration files in published artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 02:08 AM
Security Audit — agent-trust-hub — plugin-release