link-workspace-packages
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use standard package manager CLI tools (
npm,pnpm,yarn,bun) to manage workspace dependencies. These commands are typical for the stated purpose of development workflow automation. - [SAFE]: The workflow relies on local detection of lockfiles (
pnpm-lock.yaml,yarn.lock, etc.) and thepackageManagerfield inpackage.jsonto determine the appropriate environment, which is a standard and safe detection method. - [SAFE]: Example commands use generic placeholders (e.g.,
@org/ui,@org/app) and the instructions correctly advocate for using official workspace protocols (e.g.,workspace:*) rather than manual hacks, promoting secure and maintainable project configurations.
Audit Metadata