pnpm-publishing

Pass

Audited by Gen Agent Trust Hub on Feb 27, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes standard development commands such as pnpm install, pnpm lerna version, and pnpm lerna publish. These are appropriate for the task of package management and publishing.
  • [EXTERNAL_DOWNLOADS]: The skill references the use of the makage utility and standard Node.js ecosystem tools. These are fetched from the official NPM registry, which is a well-known service. The tool makage is associated with the skill's author, constructive-io.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data access or external transmission of sensitive information. The publishing process targets the standard public NPM registry.
  • [PROMPT_INJECTION]: The instructions focus purely on technical configuration and build workflows without any patterns designed to override agent safety or bypass instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 27, 2026, 05:14 AM