monorepo-navigator
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the monorepo being analyzed, which could theoretically contain malicious instructions. However, this is expected behavior for a repository analysis tool.
- Ingestion points: The
monorepo_analyzer.pyscript reads and parsespackage.jsonandpnpm-workspace.yamlfiles within the target directory. - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are used in the analysis flow.
- Capability inventory: The skill utilizes subprocess execution for monorepo CLI tools (
pnpm,nx,turbo) and provides scripts for file system analysis. - Sanitization: Data is parsed as JSON and text; no specific sanitization for prompt injection or command sequences is implemented.
- [COMMAND_EXECUTION]: The skill utilizes and provides instructions for executing standard monorepo management CLI tools (
pnpm,nx,turbo,lerna). All commands identified are common development tools used for building, testing, and managing workspaces. - [DYNAMIC_EXECUTION]: The skill provides a JavaScript utility (
scripts/gen-dep-graph.js) that usesexecSyncto run CLI commands for dependency visualization. This is a common pattern for local developer tooling.
Audit Metadata