node-release
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary objective is improving security by migrating workflows from long-lived NPM_TOKEN secrets to OIDC-based trusted publishing.
- [SAFE]: Recommends security best practices such as pinning third-party GitHub Actions to specific commit SHAs to mitigate supply chain risks.
- [SAFE]: Provides a secure bootstrap procedure for new packages that minimizes the window of exposure for temporary credentials.
- [SAFE]: The documentation references well-known and official sources (GitHub, npmjs.com) for configuration and troubleshooting.
Audit Metadata