turborepo
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOWEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- External Downloads (LOW): The skill suggests using
npx create-turbo@latest. While this downloads and executes code from the npm registry, it is the standard, documented installation method for a tool maintained by Vercel (a trusted organization). - Command Execution (INFO): The skill includes commands for running build pipelines (
turbo run build). These are standard operational commands for the described tool and do not involve suspicious parameters or privilege escalation.
Audit Metadata