npm-trusted-publishing

Pass

Audited by Socket on Feb 17, 2026

Checks
Malicious behaviorInjection, exfiltration, untrusted installs
Security concernsCredential exposure, tool/trust exploitation
Code obfuscationHidden or obfuscated code
Suspicious patternsReconnaissance, excessive autonomy, resource use
Audit Metadata
Analyzed At
Feb 17, 2026, 03:33 PM
Package URL
pkg:socket/skills-sh/pr-pm%2Fprpm%2Fnpm-trusted-publishing%2F@a3f285efb4ef92c0e3ce565624dd04eb2a7b4ecc