monorepo-management
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [SAFE]: The skill serves as a documentation and validation resource for monorepo management. It follows best practices by using placeholders for configuration secrets (e.g., 'TURBO_TOKEN=xxx') and recommends standard development tools like Turborepo, Nx, Madge, and Syncpack.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze user-provided configuration files to provide feedback. 1. Ingestion points: User-supplied 'package.json' and 'turbo.json' files are analyzed via regex patterns. 2. Boundary markers: The skill does not define specific delimiters for these inputs. 3. Capability inventory: The skill only provides textual advice and validations; it does not include scripts capable of network access, file writing, or command execution. 4. Sanitization: No explicit sanitization of user data is performed.
- [METADATA_POISONING]: The skill description includes repetitive keyword strings (e.g., 'monorepo, turborepo, nx, pnpm, workspace, caching') intended to influence search discovery, but the instructional content remains safe and matches the stated purpose.
Audit Metadata