turborepo

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The best-presented analysis (Report 1) identifies the content as benign documentation for Turborepo usage, with an overall moderate security risk mainly due to common supply-chain practices like remote caching and CI integration. The primary improvement is to correct factual inaccuracies (language/runtime composition) and to more explicitly flag potential misconfigurations in turbo.json that could affect caching and remote cache security. Overall, the fragment is suitable as a supply-chain security artifact when language accuracy is corrected.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 06:31 PM
Package URL
pkg:socket/skills-sh/mrgoonie%2Fxxxnaper%2Fturborepo%2F@bc166c81e6127920132bc9f9303562b3cf72adca