monorepo-management

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or security risks were detected in the skill instructions or reference files.
  • [EXTERNAL_DOWNLOADS]: The skill references official tools and configuration schemas from well-known and trusted organizations.
  • Evidence: Mentions official CLI tools including npx turbo, pnpm install, and @changesets/cli.
  • Evidence: References JSON schemas from turbo.build, unpkg.com, and schemastore.org.
  • [COMMAND_EXECUTION]: The skill utilizes standard shell commands for monorepo task orchestration and project management.
  • Evidence: Commands such as turbo build, pnpm install, npx changeset, and npx madge are used for their intended primary purposes within a developer environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes common repository configuration files, which represents a standard attack surface for developer-centric tools.
  • Ingestion points: The skill reads package.json, turbo.json, and pnpm-workspace.yaml to interpret workspace boundaries and task dependencies.
  • Boundary markers: Uses standard Markdown code blocks to delimit configuration examples and file content.
  • Capability inventory: The skill uses Read, Write, Edit, and Bash tools to manage the repository environment.
  • Sanitization: No specific sanitization of analyzed configuration files is required for the stated professional use case.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — monorepo-management