npm-package-publishing

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of documentation, configuration templates, and GitHub Actions workflows designed to assist developers in publishing Node-RED nodes. These are standard development artifacts and do not contain executable code for the agent itself.
  • [SAFE]: The recommended workflows utilize well-known GitHub Actions (actions/checkout, actions/setup-node) and standard npm commands. A health check using curl targets localhost, which is a common practice for integration testing.
  • [SAFE]: The skill explicitly includes a security checklist in 'references/npm-publishing-checklist.md' advising users against committing secrets, encouraging the use of Two-Factor Authentication (2FA), and promoting secure token management via GitHub Secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 08:17 AM
Security Audit — agent-trust-hub — npm-package-publishing