capgo-release-management

Pass

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses 'npx @capgo/cli@latest' to fetch and execute the official Capgo command-line tool from the npm registry. This is a standard operation for the vendor's own release management workflows.- [COMMAND_EXECUTION]: The skill provides command-line examples for performing bundle uploads, compatibility checks, and channel management using the Capgo CLI.- [SAFE]: No malicious patterns such as prompt injection, data exfiltration, or obfuscation were detected. The skill includes security-conscious advice regarding the management of private encryption keys, specifically instructing users to keep them out of version control.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 19, 2026, 12:36 AM