skills/openhands/extensions/npm/Gen Agent Trust Hub

npm

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation on how to handle npm package installations when user interaction is not possible. The guidance is standard for automation and CI/CD environments.
  • [COMMAND_EXECUTION]: The instructions suggest using the Unix 'yes' command piped into 'npm' to automatically handle confirmation prompts. While this automates command execution, it is a legitimate technique for its stated purpose and does not involve malicious intent or obfuscation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 01:58 PM
Security Audit — agent-trust-hub — npm