plugin-release
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions involve cloning the vendor's official repository from GitHub (
deepseek-ai/deepseek-harness) to facilitate artifact validation and packaging. - [COMMAND_EXECUTION]: Provides instructions for using standard development tools including
npm,pnpm, andgit, as well as the vendor-specificdshCLI. The skill includes a clear safety boundary requiring user confirmation before any publishing or tagging actions. - [DATA_EXFILTRATION]: Network operations are limited to interaction with the official npm registry and the project's own GitHub repositories for legitimate release management purposes.
- [SAFE]: No indicators of prompt injection, obfuscation, or malicious code execution were found. The skill includes explicit best-practice warnings against including credentials or private configuration files in published artifacts.
Audit Metadata