pnpm
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a high-quality documentation reference for pnpm and does not contain executable code or malicious instructions.\n- [COMMAND_EXECUTION]: The documentation includes standard CLI commands for managing dependencies and running scripts, such as pnpm install, pnpm run, and pnpm exec, which are fundamental to the tool's purpose.\n- [EXTERNAL_DOWNLOADS]: Mentions downloading packages from npm registries and using trusted GitHub Actions (e.g., actions/checkout, pnpm/action-setup) for CI/CD setup. These are well-known and reputable sources.\n- [REMOTE_CODE_EXECUTION]: Describes legitimate use cases for pnpm dlx and .pnpmfile.cjs hooks, which are built-in features for running remote binaries and customizing package resolution.
Audit Metadata