web-frameworks
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of extensive documentation and two Python utility scripts (
nextjs_init.pyandturborepo_migrate.py) used for scaffolding and project management. Analysis of these scripts confirms they perform legitimate file system operations and configuration generation without any suspicious network activity or unauthorized command execution. - [SAFE]: No instances of prompt injection, data exfiltration, or obfuscated code were found. The use of secrets in the provided GitHub Actions example follows security best practices (using
${{ secrets.TURBO_TOKEN }}). - [SAFE]: All external references and dependencies are directed toward well-known, reputable services including Next.js, Turborepo, and official package registries. The jsDelivr CDN link for RemixIcon is a standard industry practice for asset delivery.
- [SAFE]: The
.coveragefile is a standard binary SQLite database generated by the coverage.py testing tool. Although it contains absolute file paths from the developer's local environment, this is a common artifact in development repositories and does not pose a security risk to the end-user.
Audit Metadata