monorepo-management
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or security risks were detected in the skill instructions or reference files.
- [EXTERNAL_DOWNLOADS]: The skill references official tools and configuration schemas from well-known and trusted organizations.
- Evidence: Mentions official CLI tools including
npx turbo,pnpm install, and@changesets/cli. - Evidence: References JSON schemas from
turbo.build,unpkg.com, andschemastore.org. - [COMMAND_EXECUTION]: The skill utilizes standard shell commands for monorepo task orchestration and project management.
- Evidence: Commands such as
turbo build,pnpm install,npx changeset, andnpx madgeare used for their intended primary purposes within a developer environment. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes common repository configuration files, which represents a standard attack surface for developer-centric tools.
- Ingestion points: The skill reads
package.json,turbo.json, andpnpm-workspace.yamlto interpret workspace boundaries and task dependencies. - Boundary markers: Uses standard Markdown code blocks to delimit configuration examples and file content.
- Capability inventory: The skill uses
Read,Write,Edit, andBashtools to manage the repository environment. - Sanitization: No specific sanitization of analyzed configuration files is required for the stated professional use case.
Audit Metadata