npm-trusted-publishing

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and YAML templates for setting up npm trusted publishing. All external references target official registries (npmjs.org) and well-known CI/CD provider environments (GitHub Actions). The provided workflows use minimal permissions and correctly promote the elimination of long-lived secrets in favor of short-lived OIDC tokens. The example commands and configurations are standard industry practices for package publishing and do not include any malicious execution patterns, data exfiltration, or obfuscation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 11:52 AM
Security Audit — agent-trust-hub — npm-trusted-publishing