{"id":25636,"plugin_id":"plugin_asdk_app_6a6a699e6f3481918d5e6034432894f2","kind":"catalog","collection_source":null,"comparison_source":null,"observed_at":"2026-10-01T18:00:02.555Z","digest":"a268e2d1335468a42059a47e0f71096a749a28767e1712b42333cf81106a2df8","against":2157,"payload":{"id":"plugin_asdk_app_6a6a699e6f3481918d5e6034432894f2","name":"app-6a6a699e6f3481918d5e6034432894f2","scope":"GLOBAL","status":"ENABLED","release":{"id":"pluginrel_1e35db74309c81918693771d0841da81","skills":[{"name":"ci-pr-gate","interface":{"brand_color":null,"iconography":"code","display_name":"ci-pr-gate","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Turn a dependency change — a before/after package.json/lockfile snapshot, or one or more named \"bump X from A to B\" upgrades — into one deterministic PASS/WARN/FAIL verdict formatted for a CI check or PR-comment bot, not a conversational report. Use when the user explicitly wants a mergeable/blocking verdict, a \"CI gate,\" a PR status comment, or asks \"should this PR be blocked,\" \"is this safe to merge,\" \"gate this dependency bump.\" Not for a plain explanation of what changed in a diff (dependency-audit's own snapshot-diff flow already covers that conversationally) and not for a single already-installed package's trust investigation (package-trust-check)."},"description":"Turn a dependency change — a before/after package.json/lockfile snapshot, or one or more named \"bump X from A to B\" upgrades — into one deterministic PASS/WARN/FAIL verdict formatted for a CI check or PR-comment bot, not a conversational report. Use when the user explicitly wants a mergeable/blocking verdict, a \"CI gate,\" a PR status comment, or asks \"should this PR be blocked,\" \"is this safe to merge,\" \"gate this dependency bump.\" Not for a plain explanation of what changed in a diff (dependency-audit's own snapshot-diff flow already covers that conversationally) and not for a single already-installed package's trust investigation (package-trust-check).","plugin_release_skill_id":"pluginrsk_6aa8829ab7cc8191937c29d6b3021817"},{"name":"dependency-audit","interface":{"brand_color":null,"iconography":"radar","display_name":"dependency-audit","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance."},"description":"Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance.","plugin_release_skill_id":"pluginrsk_6aa8825150e481919b1acdd51722c07e"},{"name":"incident-response","interface":{"brand_color":null,"iconography":"bolt","display_name":"incident-response","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Turn a flagged npm supply-chain finding — or just a vague, non-technical description of one (\"this package looks sketchy,\" \"someone said we got hacked,\" \"npm install did something weird\") — into concrete remediation steps. Use whenever the user wants to know what to actually do about a suspicious/compromised/flagged package, however precisely or vaguely they describe it — not for the initial trust/vulnerability investigation itself (see package-trust-check/dependency-audit for that)."},"description":"Turn a flagged npm supply-chain finding — or just a vague, non-technical description of one (\"this package looks sketchy,\" \"someone said we got hacked,\" \"npm install did something weird\") — into concrete remediation steps. Use whenever the user wants to know what to actually do about a suspicious/compromised/flagged package, however precisely or vaguely they describe it — not for the initial trust/vulnerability investigation itself (see package-trust-check/dependency-audit for that).","plugin_release_skill_id":"pluginrsk_6aa8825cc83881919643e10ecddf1b44"},{"name":"new-dependency-evaluation","interface":{"brand_color":null,"iconography":"heart","display_name":"new-dependency-evaluation","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Help decide what to add as a NEW npm dependency — comparing 2-5 named candidates for the same job, evaluating one named candidate against its real peers, or shortlisting candidates from a described need, before anything is installed. Use for \"which should we use for X,\" \"axios vs got vs node-fetch,\" \"is X a good pick for Y,\" \"what should we use to do Z,\" \"should we add X or is there something better.\" Not for auditing packages already in the project (see dependency-audit), not for a deep single-package compromise/trust investigation (see package-trust-check), and not for a plain factual question with no choice being made (\"what does X do\")."},"description":"Help decide what to add as a NEW npm dependency — comparing 2-5 named candidates for the same job, evaluating one named candidate against its real peers, or shortlisting candidates from a described need, before anything is installed. Use for \"which should we use for X,\" \"axios vs got vs node-fetch,\" \"is X a good pick for Y,\" \"what should we use to do Z,\" \"should we add X or is there something better.\" Not for auditing packages already in the project (see dependency-audit), not for a deep single-package compromise/trust investigation (see package-trust-check), and not for a plain factual question with no choice being made (\"what does X do\").","plugin_release_skill_id":"pluginrsk_6aa882a41b3481918b3b93986c8d4a7a"},{"name":"package-trust-check","interface":{"brand_color":null,"iconography":"hierarchy","display_name":"package-trust-check","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\""},"description":"Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\"","plugin_release_skill_id":"pluginrsk_6aa882a7264c8191a5daa9e688e5e052"}],"app_ids":["asdk_app_6a6a699e6f3481918d5e6034432894f2"],"version":"3.0.0","keywords":[],"interface":{"category":"Developer Tools","logo_url":"https://files.openai.com/content?id=file_0000000063f882468dd752086f6c99a7","brand_color":null,"website_url":"https://npmscan.com/","capabilities":[],"logo_url_dark":"https://files.openai.com/content?id=file_00000000630c8243aee15c270c53c093","default_prompt":"Find npm packages for parsing CSV files","developer_name":"SHYNGYS SHYNBOLATOV","default_prompts":["Find npm packages for parsing CSV files","Is minimist 1.2.5 safe to use, or do I need to upgrade?","Audit my package.json dependencies for vulnerabilities and risky install scripts"],"screenshot_urls":[],"long_description":"Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.","composer_icon_url":"https://files.openai.com/content?id=file_000000004a3481f4940425585a62fda1","short_description":"npm package & vuln lookups","plugin_category_id":"developer tools","privacy_policy_url":"https://npmscan.com/privacy","terms_of_service_url":"https://npmscan.com/terms","composer_icon_dark_url":"https://files.openai.com/content?id=file_00000000620481f4902f42d39eff7d12"},"description":"Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.","app_manifest":{"apps":{"app-6a6a699e6f3481918d5e6034432894f2":{"id":"asdk_app_6a6a699e6f3481918d5e6034432894f2","required":true}}},"display_name":"NPMScan","app_templates":[],"onboarding_skill_name":null,"requires_local_executor":false},"created_at":"2026-07-29T20:59:10.652584Z","is_template":false,"connector_id":"asdk_app_6a6a699e6f3481918d5e6034432894f2","discoverability":"LISTED","canonical_app_id":"asdk_app_6a6a699e6f3481918d5e6034432894f2"},"changes":[{"path":"/release/description","type":"changed","before":"Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing; check an exact version pinned in a lockfile; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; browse the latest reviewed npm advisories, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.","after":"Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com."},{"path":"/release/id","type":"changed","before":"pluginrel_abc190d64f008191af6c32be52a9c4df","after":"pluginrel_1e35db74309c81918693771d0841da81"},{"path":"/release/interface/developer_name","type":"changed","before":"SHYNGGYS SHYNBOLATOV","after":"SHYNGYS SHYNBOLATOV"},{"path":"/release/interface/long_description","type":"changed","before":"Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing; check an exact version pinned in a lockfile; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; browse the latest reviewed npm advisories, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.","after":"Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com."},{"path":"/release/skills","type":"changed","before":[{"name":"dependency-audit","interface":{"brand_color":null,"iconography":"radar","display_name":"dependency-audit","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance."},"description":"Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance.","plugin_release_skill_id":"pluginrsk_6a976bffb2188191ad0b8770ba42e478"},{"name":"package-trust-check","interface":{"brand_color":null,"iconography":"radar","display_name":"package-trust-check","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\""},"description":"Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\"","plugin_release_skill_id":"pluginrsk_6a976c0940308191a0bccf9befcd4cbc"}],"after":[{"name":"ci-pr-gate","interface":{"brand_color":null,"iconography":"code","display_name":"ci-pr-gate","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Turn a dependency change — a before/after package.json/lockfile snapshot, or one or more named \"bump X from A to B\" upgrades — into one deterministic PASS/WARN/FAIL verdict formatted for a CI check or PR-comment bot, not a conversational report. Use when the user explicitly wants a mergeable/blocking verdict, a \"CI gate,\" a PR status comment, or asks \"should this PR be blocked,\" \"is this safe to merge,\" \"gate this dependency bump.\" Not for a plain explanation of what changed in a diff (dependency-audit's own snapshot-diff flow already covers that conversationally) and not for a single already-installed package's trust investigation (package-trust-check)."},"description":"Turn a dependency change — a before/after package.json/lockfile snapshot, or one or more named \"bump X from A to B\" upgrades — into one deterministic PASS/WARN/FAIL verdict formatted for a CI check or PR-comment bot, not a conversational report. Use when the user explicitly wants a mergeable/blocking verdict, a \"CI gate,\" a PR status comment, or asks \"should this PR be blocked,\" \"is this safe to merge,\" \"gate this dependency bump.\" Not for a plain explanation of what changed in a diff (dependency-audit's own snapshot-diff flow already covers that conversationally) and not for a single already-installed package's trust investigation (package-trust-check).","plugin_release_skill_id":"pluginrsk_6aa8829ab7cc8191937c29d6b3021817"},{"name":"dependency-audit","interface":{"brand_color":null,"iconography":"radar","display_name":"dependency-audit","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance."},"description":"Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance.","plugin_release_skill_id":"pluginrsk_6aa8825150e481919b1acdd51722c07e"},{"name":"incident-response","interface":{"brand_color":null,"iconography":"bolt","display_name":"incident-response","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Turn a flagged npm supply-chain finding — or just a vague, non-technical description of one (\"this package looks sketchy,\" \"someone said we got hacked,\" \"npm install did something weird\") — into concrete remediation steps. Use whenever the user wants to know what to actually do about a suspicious/compromised/flagged package, however precisely or vaguely they describe it — not for the initial trust/vulnerability investigation itself (see package-trust-check/dependency-audit for that)."},"description":"Turn a flagged npm supply-chain finding — or just a vague, non-technical description of one (\"this package looks sketchy,\" \"someone said we got hacked,\" \"npm install did something weird\") — into concrete remediation steps. Use whenever the user wants to know what to actually do about a suspicious/compromised/flagged package, however precisely or vaguely they describe it — not for the initial trust/vulnerability investigation itself (see package-trust-check/dependency-audit for that).","plugin_release_skill_id":"pluginrsk_6aa8825cc83881919643e10ecddf1b44"},{"name":"new-dependency-evaluation","interface":{"brand_color":null,"iconography":"heart","display_name":"new-dependency-evaluation","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Help decide what to add as a NEW npm dependency — comparing 2-5 named candidates for the same job, evaluating one named candidate against its real peers, or shortlisting candidates from a described need, before anything is installed. Use for \"which should we use for X,\" \"axios vs got vs node-fetch,\" \"is X a good pick for Y,\" \"what should we use to do Z,\" \"should we add X or is there something better.\" Not for auditing packages already in the project (see dependency-audit), not for a deep single-package compromise/trust investigation (see package-trust-check), and not for a plain factual question with no choice being made (\"what does X do\")."},"description":"Help decide what to add as a NEW npm dependency — comparing 2-5 named candidates for the same job, evaluating one named candidate against its real peers, or shortlisting candidates from a described need, before anything is installed. Use for \"which should we use for X,\" \"axios vs got vs node-fetch,\" \"is X a good pick for Y,\" \"what should we use to do Z,\" \"should we add X or is there something better.\" Not for auditing packages already in the project (see dependency-audit), not for a deep single-package compromise/trust investigation (see package-trust-check), and not for a plain factual question with no choice being made (\"what does X do\").","plugin_release_skill_id":"pluginrsk_6aa882a41b3481918b3b93986c8d4a7a"},{"name":"package-trust-check","interface":{"brand_color":null,"iconography":"hierarchy","display_name":"package-trust-check","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\""},"description":"Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\"","plugin_release_skill_id":"pluginrsk_6aa882a7264c8191a5daa9e688e5e052"}]},{"path":"/release/version","type":"changed","before":"2.0.0","after":"3.0.0"}],"summary":"Fields changed: 6. /release/description, /release/id, /release/interface/developer_name, /release/interface/long_description, /release/skills, /release/version.","summary_kind":"deterministic","summary_metadata":{}}