nextjs-turborepo
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE] (SAFE): The skill consists primarily of markdown documentation and reference guides. While it mentions two Python scripts (nextjs-init.py and turborepo-migrate.py) in the SKILL.md file, these scripts are not included in the provided file bundle. The init.py file is empty, and the requirements.txt files only list standard testing tools.\n- [CREDENTIALS_UNSAFE] (SAFE): No hardcoded secrets, API keys, or tokens were detected. The documentation correctly identifies the use of environment variables and GitHub secrets (e.g., TURBO_TOKEN) for managing sensitive information in CI/CD pipelines following industry best practices.\n- [EXTERNAL_DOWNLOADS] (SAFE): The skill references official and trusted tools such as create-next-app and create-turbo from Vercel. These are standard, industry-recognized tools for the technology stack described and do not pose a risk. The node packages mentioned are all standard web development libraries.\n- [PROMPT_INJECTION] (SAFE): The markdown content does not contain any instructions that attempt to override AI behavior or bypass safety filters. The language is purely instructional and focused on developer productivity and framework usage.
Audit Metadata