Typescript Package Publication Integrity

Use this skill to statically review npm package publication integrity: whether publish authority relies on OIDC-based trusted publishing rather than a long-lived token, whether the published artifact carries provenance a consumer can verify, whether the release-automation trust path resists compromise, whether the packed tarball and its declarations/source maps expose only what is intended, whether publish-time lifecycle scripts are justified, and whether registry/scope configuration resists dependency confusion. Reads the publish workflow and sanitized configuration only; it never runs a publish or signs anything.

VincentChuWaiChow Updated

File contents

VincentChuWaiChow/vanguard-frontier-agentic/tree/main/skills/typescript/typescript-package-publication-integrity commit cd31745c8d

Frequently asked questions

npx skillmds@latest add vincentchuwaichow/typescript-package-publication-integrity