monorepo-tooling

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains no suspicious commands, obfuscation, or data exfiltration patterns. It follows best practices by explicitly advising against committing secrets to version control.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a limited attack surface as it processes workspace configuration files (e.g., package.json, pnpm-workspace.yaml, turbo.json). This risk is managed by instructions that define clear scope boundaries and prioritize read-only tool access.
  • [SAFE]: All external links point to the author's official GitHub repository and the public npm registry, which are well-known and expected sources for development tooling.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 03:03 AM
Security Audit — agent-trust-hub — monorepo-tooling