plugin-publish

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard documentation and procedural guidance for software publishing. It does not contain any malicious patterns such as prompt injection, obfuscation, or unauthorized data exfiltration.
  • [COMMAND_EXECUTION]: The skill instructs the agent to guide users through common development commands, including pnpm build, pnpm test, and npm publish. These commands are standard for the intended use case and are executed locally within the developer's environment.
  • [DATA_EXFILTRATION]: No suspicious network operations or exfiltration patterns were detected. The skill specifically highlights security best practices by instructing users to exclude sensitive files like .env from the published package.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 10:39 PM
Security Audit — agent-trust-hub — plugin-publish