turborepo
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- Domain-Specific Guidance: The skill focuses entirely on providing architectural and configuration guidance for Turborepo. It contains no executable scripts or commands that could compromise the host system.
- Trusted Vendor Integration: All external references, such as documentation links and GitHub Actions, point to official and trusted domains (e.g., turborepo.dev, vercel.com, github.com/vercel). These are recognized as safe vendor resources.
- Standard Security Practices: The documentation correctly identifies and recommends secure practices for handling sensitive information, such as using GitHub Secrets for
TURBO_TOKENandAWS_ACCESS_KEY_ID, rather than hardcoding them in configurations. - No Malicious Patterns: The skill was evaluated for prompt injection, obfuscation, data exfiltration, and other threat vectors, and no malicious patterns were identified. The instructional content is professional and focused on build system optimization.
Audit Metadata