deploy-to-maven-central

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [DATA_EXFILTRATION]: The skill reads sensitive deployment credentials, including GPG signing passwords and Sonatype account credentials, from the project's local.properties file.\n- [COMMAND_EXECUTION]: Uses the bash tool to execute local Gradle build commands (./gradlew) and curl for interacting with the deployment server.\n- [EXTERNAL_DOWNLOADS]: Performs network operations to communicate with the well-known Sonatype OSSRH staging API (ossrh-staging-api.central.sonatype.com) to facilitate the library upload.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 10:51 PM
Security Audit — agent-trust-hub — deploy-to-maven-central