plugin-publish
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard documentation and procedural guidance for software publishing. It does not contain any malicious patterns such as prompt injection, obfuscation, or unauthorized data exfiltration.
- [COMMAND_EXECUTION]: The skill instructs the agent to guide users through common development commands, including
pnpm build,pnpm test, andnpm publish. These commands are standard for the intended use case and are executed locally within the developer's environment. - [DATA_EXFILTRATION]: No suspicious network operations or exfiltration patterns were detected. The skill specifically highlights security best practices by instructing users to exclude sensitive files like
.envfrom the published package.
Audit Metadata