npm-trusted-publishing
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and YAML templates for setting up npm trusted publishing. All external references target official registries (npmjs.org) and well-known CI/CD provider environments (GitHub Actions). The provided workflows use minimal permissions and correctly promote the elimination of long-lived secrets in favor of short-lived OIDC tokens. The example commands and configurations are standard industry practices for package publishing and do not include any malicious execution patterns, data exfiltration, or obfuscation.
Audit Metadata