monorepo-management
Warn
Audited by Socket on Mar 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill presents a coherent, enterprise-focused monorepo management solution with appropriate use of Turborepo/Nx and CI/CD patterns. The primary security considerations revolve around the self-hosted remote cache endpoints and the orchestration code that executes shell commands. If properly secured (authenticated cache endpoints, restricted IAM roles, robust validation of task inputs, and isolation of build artifacts), the footprint can remain-benign and proportionate to the stated purpose. However, the presence of an unprotected cache HTTP API and potential command execution via orchestrate.ts are notable risk vectors that should be addressed before deployment in a production environment.
Confidence: 65%Severity: 50%
Audit Metadata