NPM Package Vulnerability Runbook
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of markdown documentation and metadata. It contains no executable scripts, shell commands, or tool definitions.
- [METADATA_POISONING]: The skill's frontmatter includes self-authoritative claims regarding its safety status, specifically the "verification: security_reviewed" field. Additionally, the author is listed as "npm, Inc." in the metadata, which conflicts with the external author context. These are considered metadata discrepancies rather than functional risks due to the lack of code.
- [SAFE]: All external links provided in the documentation target well-known, official domains (npmjs.com) or the author's own domain (agentskillexchange.com).
Audit Metadata