npm
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill coordinates several CLI tools including
npm,op(1Password),jq, andtmuxto automate authenticated registry tasks. - [DATA_EXFILTRATION]: Scripts implement a dedicated
redactfunction that uses regular expressions to identify and remove npm tokens and One-Time Passwords (OTPs) from all console output and log files, minimizing the risk of credential leakage during operation. - [DYNAMIC_EXECUTION]: The
npm-auth-login.mjsscript utilizes dynamic loading to find and import thenpm-profilelibrary from the system's global node_modules directory, enabling programmatic registry login without requiring a localnode_modulesfolder in the skill directory. - [INDIRECT_PROMPT_INJECTION]: The package reservation logic accepts user-supplied names which are used to generate temporary
package.jsonfiles for placeholder releases. * Ingestion points: Command-line arguments inreserve-packages.sh(e.g.,scripts/reserve-packages.sh package-one). * Boundary markers: None; inputs are placed directly into a JSON template. * Capability inventory: File writing viacatandnpm publishexecution. * Sanitization: No input validation is performed on package names, representing a theoretical surface for schema confusion, though mitigated by the script's use of a temporary directory and isolated execution environment.
Audit Metadata