pnpm-publishing
Pass
Audited by Gen Agent Trust Hub on Feb 27, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes standard development commands such as
pnpm install,pnpm lerna version, andpnpm lerna publish. These are appropriate for the task of package management and publishing. - [EXTERNAL_DOWNLOADS]: The skill references the use of the
makageutility and standard Node.js ecosystem tools. These are fetched from the official NPM registry, which is a well-known service. The toolmakageis associated with the skill's author, constructive-io. - [DATA_EXFILTRATION]: No evidence of unauthorized data access or external transmission of sensitive information. The publishing process targets the standard public NPM registry.
- [PROMPT_INJECTION]: The instructions focus purely on technical configuration and build workflows without any patterns designed to override agent safety or bypass instructions.
Audit Metadata