turborepo
Pass
Audited by Gen Agent Trust Hub on Mar 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or security vulnerabilities were identified. The skill's content is educational and strictly focused on its primary purpose of monorepo orchestration.
- [PROMPT_INJECTION]: The instructions do not contain any attempts to override agent behavior, bypass safety filters, or extract system prompts. All directions are task-oriented and relate to Turborepo configuration.
- [EXTERNAL_DOWNLOADS]: References to external domains (such as turborepo.dev and vercel.com) are limited to official documentation, schemas, and trusted cloud services. No downloads from untrusted sources were detected.
- [DATA_EXFILTRATION]: There is no evidence of hardcoded credentials or unauthorized data access. The mention of environment variables like TURBO_TOKEN and API_KEY is within the context of standard configuration practices and uses placeholders or descriptive names rather than sensitive data.
- [COMMAND_EXECUTION]: The skill documents standard Turborepo CLI commands (e.g.,
turbo run,npx turbo-ignore). These are provided as part of legitimate build and deployment workflows and do not execute malicious scripts.
Audit Metadata