turborepo
Pass
Audited by Gen Agent Trust Hub on Apr 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides detailed guidance on configuring Turborepo, including task pipelines, caching, and environment variable management, adhering to official documentation standards.
- [SAFE]: No evidence of prompt injection, data exfiltration, or malicious obfuscation was found across the 26 files analyzed.
- [SAFE]: The skill emphasizes secure practices, such as using environment variables for secrets in CI/CD pipelines (e.g., GITHUB_TOKEN, TURBO_TOKEN) and correctly defining task outputs for caching.
- [SAFE]: Remote code execution and privilege escalation patterns are absent; all recommended tools (e.g., syncpack, manypkg) are well-known utilities in the JavaScript ecosystem.
- [SAFE]: The workflow for the agent is clearly defined and focuses on assisting the user with legitimate development tasks within a monorepo structure.
Audit Metadata