capgo-release-management
Pass
Audited by Gen Agent Trust Hub on Mar 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses 'npx @capgo/cli@latest' to fetch and execute the official Capgo command-line tool from the npm registry. This is a standard operation for the vendor's own release management workflows.- [COMMAND_EXECUTION]: The skill provides command-line examples for performing bundle uploads, compatibility checks, and channel management using the Capgo CLI.- [SAFE]: No malicious patterns such as prompt injection, data exfiltration, or obfuscation were detected. The skill includes security-conscious advice regarding the management of private encryption keys, specifically instructing users to keep them out of version control.
Audit Metadata