skills/steipete/agent-scripts/npm/Gen Agent Trust Hub

npm

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill coordinates several CLI tools including npm, op (1Password), jq, and tmux to automate authenticated registry tasks.
  • [DATA_EXFILTRATION]: Scripts implement a dedicated redact function that uses regular expressions to identify and remove npm tokens and One-Time Passwords (OTPs) from all console output and log files, minimizing the risk of credential leakage during operation.
  • [DYNAMIC_EXECUTION]: The npm-auth-login.mjs script utilizes dynamic loading to find and import the npm-profile library from the system's global node_modules directory, enabling programmatic registry login without requiring a local node_modules folder in the skill directory.
  • [INDIRECT_PROMPT_INJECTION]: The package reservation logic accepts user-supplied names which are used to generate temporary package.json files for placeholder releases. * Ingestion points: Command-line arguments in reserve-packages.sh (e.g., scripts/reserve-packages.sh package-one). * Boundary markers: None; inputs are placed directly into a JSON template. * Capability inventory: File writing via cat and npm publish execution. * Sanitization: No input validation is performed on package names, representing a theoretical surface for schema confusion, though mitigated by the script's use of a temporary directory and isolated execution environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:27 PM
Security Audit — agent-trust-hub — npm