Back to skills
SKILL.md
Monorepo Management
ASecurityUse when executing, coordinating, planning, or reviewing monorepo management agent workflows, cognitive loops, and architecture standards.
- 5 stars
- 0 votes
- 0 copies
- 1 view
- Added September 27, 2026
Works with
Security analysis
100/100npx -y skills add Harmitx7/tribunal-kit --skill monorepo-management --agent claude-codeAre you the author of Monorepo Management?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/harmitx7-monorepo-management)---
name: monorepo-management
description: "Use when executing, coordinating, planning, or reviewing monorepo management agent workflows, cognitive loops, and architecture standards."
version: 6.0.0
last-updated: 2026-09-29
skills:
- cicd-pro
- codebase-design
- lint-and-validate
tools: Read, Grep, Glob, Bash, Edit, Write
scripts-binding:
- .agent/scripts/lint_runner.js
- .agent/scripts/verify_all.js
---
# Monorepo Management β Scaling Multi-Package Projects
## Mandatory Pre-Flight Context Inspection
Before reading, generating, or refactoring code in the `monorepo-management` domain, inspect these 5 critical parameters:
1. **System Boundaries & Dependencies**: Verify that all required dependencies exist in target package manifests and environment paths.
2. **Runtime Context & Platform Invariants**: Confirm target platform constraints (Node.js, Browser, Mobile OS, Edge runtime) before applying APIs.
3. **Execution Guardrails**: Identify potential side-effects, state mutations, and unhandled asynchronous exceptions.
4. **Validation & Type Contracts**: Validate input data schemas and strict type constraints across all module interfaces.
5. **Observability & Proof of Execution**: Ensure execution produces tangible verification signals (terminal output, tests, metrics).
## Activation Boundaries
- **Activate when:** Use when executing, coordinating, planning, or reviewing monorepo management agent workflows, cognitive loops, and architecture standards.
- **DO NOT activate when:** The task falls outside the `monorepo-management` domain or is managed by a different dedicated specialist agent.
## π Multi-Pass Execution Protocol
| Pass | Phase | Core Action | Adaptive Depth |
|:---|:---|:---|:---|
| **Pass 1** | **Understand** | Deconstruct the user's explicit objective, implicit requirements, and platform constraints. | Fast / Standard / Deep |
| **Pass 2** | **Plan** | Decompose task into smallest logical steps; map dependencies, affected files, and tool calls. | Standard / Deep |
| **Pass 3** | **Execute** | Implement solution with production-grade craft, zero placeholders, and strict typing. | All Modes |
| **Pass 4** | **Verify** | Run linters, unit tests, or compiler checks to validate structural correctness. | All Modes |
| **Pass 5** | **Attack & Falsify** | Perform adversarial search for edge-case failures, counterexamples, race conditions, and traps. | Standard / Deep |
| **Pass 6** | **Harden** | Eliminate discovered friction, optimize performance, and harden error boundaries. | Standard / Deep |
| **Pass 7** | **Quality Gate** | Enforce Verification-Before-Completion (VBC) with concrete terminal proof before finalizing. | All Modes |
---
## π οΈ Technical Architecture & Reference Recipes
## Hallucination Traps (Read First)
- β Publishing internal packages to npm when they're meant to stay private -> β
Internal packages use `"private": true` and workspace protocol `"workspace:*"`
- β Putting all shared code in a single `packages/shared` dump -> β
Split by domain: `packages/ui`, `packages/config`, `packages/utils`
- β Running all tests on every PR regardless of what changed -> β
Use affected/changed detection (Turborepo `--filter`, Nx `affected`)
---
## Tool Selection
```
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β When to Use What β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β pnpm workspaces β Package linking only, no build orchestrationβ
β Turborepo β Fast builds, simple config, Vercel ecosystemβ
β Nx β Enterprise, generators, dependency graph UI β
β npm workspaces β Zero-dep, basic linking (limited features) β
β Yarn workspaces β Legacy projects already using Yarn β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Recommendation: pnpm + Turborepo for most projects β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
```
---
## Directory Structure
```
my-monorepo/
βββ apps/
β βββ web/ # Next.js frontend
β β βββ package.json
β β βββ tsconfig.json
β βββ api/ # Fastify/Express backend
β β βββ package.json
β β βββ tsconfig.json
β βββ mobile/ # React Native app
β βββ package.json
βββ packages/
β βββ ui/ # Shared React components
β β βββ src/
β β βββ package.json
β β βββ tsconfig.json
β βββ config/ # Shared ESLint, TypeScript, Prettier configs
β β βββ eslint/
β β βββ typescript/
β β βββ package.json
β βββ utils/ # Shared pure functions
β β βββ package.json
β βββ db/ # Shared database client + schemas
β βββ package.json
βββ turbo.json
βββ pnpm-workspace.yaml
βββ package.json # Root β devDependencies only
βββ tsconfig.base.json # Shared TS config extended by all
```
---
## pnpm Workspace Setup
```yaml
# pnpm-workspace.yaml
packages:
- 'apps/*'
- 'packages/*'
```
```json
// Root package.json
{
"name": "my-monorepo",
"private": true,
"scripts": {
"dev": "turbo run dev",
"build": "turbo run build",
"lint": "turbo run lint",
"test": "turbo run test",
"clean": "turbo run clean"
},
"devDependencies": {
"turbo": "^2.0.0"
}
}
```
```json
// packages/ui/package.json
{
"name": "@myorg/ui",
"version": "0.0.0",
"private": true,
"main": "./src/index.ts",
"types": "./src/index.ts",
"exports": {
".": "./src/index.ts",
"./button": "./src/button.tsx",
"./card": "./src/card.tsx"
},
"peerDependencies": {
"react": "^19.0.0",
"react-dom": "^19.0.0"
}
}
```
```json
// apps/web/package.json β consuming internal package
{
"name": "web",
"dependencies": {
"@myorg/ui": "workspace:*",
"@myorg/utils": "workspace:*"
}
}
```
---
## Turborepo Configuration
```json
// turbo.json
{
"$schema": "https://turbo.build/schema.json",
"globalDependencies": ["**/.env.*local"],
"tasks": {
"build": {
"dependsOn": ["^build"],
"outputs": ["src/**", ".next/**", "!.next/cache/**"]
},
"dev": {
"cache": false,
"persistent": true
},
"lint": {
"dependsOn": ["^build"]
},
"test": {
"dependsOn": ["^build"],
"outputs": ["coverage/**"]
},
"clean": {
"cache": false
}
}
}
```
```
Key concepts:
"^build" = Run build in dependencies FIRST (topological)
"dependsOn" = Task ordering β lint waits for build
"outputs" = What gets cached β skip re-runs if unchanged
"persistent" = Long-running (dev servers) β never cached
"cache: false" = Always run, never skip
```
---
## Shared TypeScript Configuration
```json
// tsconfig.base.json (root)
{
"compilerOptions": {
"strict": true,
"target": "ES2022",
"module": "ESNext",
"moduleResolution": "bundler",
"esModuleInterop": true,
"skipLibCheck": true,
"forceConsistentCasingInFileNames": true,
"declaration": true,
"declarationMap": true,
"sourceMap": true,
"isolatedModules": true,
"resolveJsonModule": true
}
}
```
```json
// apps/web/tsconfig.json
{
"extends": "../../tsconfig.base.json",
"compilerOptions": {
"jsx": "preserve",
"lib": ["dom", "dom.iterable", "ES2022"],
"outDir": "./dist"
},
"include": ["src/**/*", "../../packages/*/src/**/*"]
}
```
---
## Change Detection (Only Build What Changed)
```bash
# Turborepo β filter by affected packages
turbo run build --filter=...[HEAD~1] # packages changed since last commit
turbo run test --filter=web... # web app + its dependencies
turbo run lint --filter=@myorg/ui # specific package only
# CI: Only run tests for changed packages
turbo run test --filter="[origin/main...HEAD]"
```
```yaml
# GitHub Actions β with Turborepo cache
- name: Build & Test (cached)
run: npx turbo run build test lint --filter="[origin/main...HEAD]"
env:
TURBO_TOKEN: ${{ secrets.TURBO_TOKEN }}
TURBO_TEAM: ${{ vars.TURBO_TEAM }}
```
---
## Versioning Strategies
```
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Fixed (recommended for apps) β
β All packages share one version. Simple. One changelog. β
β Example: v1.2.3 applies to web, api, ui, utils, db β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Independent (for published libraries) β
β Each package has its own version + changelog. β
β Example: @myorg/ui@2.1.0, @myorg/utils@1.4.2 β
β Tools: Changesets, Lerna β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Recommendation: β
β Internal monorepo (1 team) β Fixed versioning β
β Open-source multi-package β Independent + Changesets β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
```
---
## Internal Package Design Rules
```
β
Internal packages are "private": true β never published to npm
β
Use workspace protocol: "@myorg/ui": "workspace:*"
β
Export raw TypeScript (src/index.ts) β let the consuming app bundle it
β
One package per domain: ui, utils, config, db β NOT one giant "shared"
β
Peer dependencies for React/framework β don't bundle the framework
β Don't create a package for 1-2 functions β inline until it's reused 3+ times
β Don't publish internal packages to npm "just in case"
β Don't share mutable state across packages β each package is a pure module
β Don't put app-specific code in packages/ β only truly shared code
```
---
## Anti-Patterns
```
β Running all CI checks on every package for every PR β use affected detection
β Circular dependencies between packages β topological ordering must be acyclic
β Mixing CommonJS and ESM in the same monorepo β standardize on ESM
β Installing devDependencies in every package β hoist shared devDeps to root
β No lockfile β pnpm-lock.yaml MUST be committed
β Using relative paths (../../packages/ui) β use workspace:* protocol
β Giant "shared" package β splits into domain-focused packages
```
## π¨ Edge-Case & Failure Mode Matrix
| Scenario | Risk | Production Mitigation |
|:---|:---|:---|
| **Empty or Null Inputs** | Unhandled exception or unexpected rendering collapse | Enforce fallback guards, optional chaining, and explicit empty state handlers |
| **Network Timeout / Latency** | Hanging operations or duplicate side-effects | Implement bounded abort controllers, exponential backoff, and idempotency keys |
| **Concurrency / Race Conditions** | Stale state overwrite or inconsistent data mutations | Use atomic transactions, mutex locking, or cancel-on-resubmit controls |
| **Invalid Schema / Malformed Payload** | Downstream runtime errors or security injection | Validate boundary payloads with Zod/Pydantic schemas prior to execution |
| **Resource / Memory Saturation** | OOM errors, frame drops, or memory leaks | Clean up listeners, cancel active timers, and enforce pagination/virtualization |
## ποΈ Tribunal Verification & Guardrails
**Active Reviewers:** `orchestrator` Β· `agent-organizer` Β· `logic-reviewer`
**Slash Command:** `/review` or `/tribunal-full`
### π¬ Evidence Standard (Tri-State Verification)
Every finding, audit statement, or completion claim must classify its factual certainty:
- **`[OBSERVED]`**: Directly confirmed in the codebase or verified via executed terminal command.
- **`[INFERRED]`**: Logically deduced from code patterns, architectural data flow, or schema relations.
- **`[UNVERIFIED]`**: Speculative hypothesis or runtime possibility requiring active testing or measurement.
### β
Pre-Flight Self-Audit Checklist
```
β
Did I deconstruct the root objective before proposing architecture?
β
Did I identify dependencies, bottlenecks, and parallelizable sub-tasks?
β
Did I avoid over-engineering and select the simplest effective pattern?
β
Did I verify assumptions with concrete file reads instead of speculation?
β
Did I establish measurable verification criteria before completion?
```
### π Verification-Before-Completion (VBC) Protocol
**CRITICAL:** You must follow a strict "evidence-based closeout" state machine.
- β **Forbidden:** Declaring a task complete because the output "looks correct."
- β
**Required:** You are explicitly forbidden from finalizing any task without providing **concrete evidence** (terminal output, passing test suites, compiler success, or equivalent operational proof) that your output works as intended.
Attribution
Comments
Loading commentsβ¦