monorepo

monorepo is a skill for Claude Code from avibebuilder/claude-prime. It costs 132 tokens per session (1,112 once invoked), scanned A, original, MIT.

Guidance for developing a monorepo, a repository that contains several related applications or libraries, with pnpm workspaces and Turborepo. It covers package layout, shared configuration, dependencies, build order, caching, and environment variables.

In plain words
What is it for?
Adding packages, sharing TypeScript, ESLint, or Prettier configuration, managing internal dependencies, ordering builds, and limiting CI work to changed packages.
Why use it?
It helps keep multiple packages consistent and prevents common problems such as incorrect build order, duplicate lockfiles, or broken cross-package imports. It also makes build caching and CI scope explicit.

Skill for Claude Code

Written for Claude Code: installed under .claude/.

Good fit Adding packages, sharing TypeScript, ESLint, or Prettier configuration, managing internal dependencies, ordering builds, and limiting CI work to changed packages.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/avibebuilder/claude-prime/monorepo
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add avibebuilder/claude-prime --skill monorepo
Clone the repo
git clone --depth 1 https://github.com/avibebuilder/claude-prime

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for monorepo

README.md
[![agentmods](https://agentmods.dev/badge/skills/avibebuilder/claude-prime/monorepo.svg)](https://agentmods.dev/skills/avibebuilder/claude-prime/monorepo)
Your own site
<a href="https://agentmods.dev/skills/avibebuilder/claude-prime/monorepo"><img src="https://agentmods.dev/badge/skills/avibebuilder/claude-prime/monorepo.svg" alt="Measured on agentmods" height="20"></a>
Per session 132 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,112 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00132 $0.01112
Opus 5 $0.00066 $0.00556
Sonnet 5 $0.00026 $0.00222
Haiku 4.5 $0.00013 $0.00111

Measured 8d ago against content hash c557279f38a9, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

monorepo scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/starter-skills/monorepo/SKILL.md · 60 lines

How it starts

The opening of the file, as written. The whole thing — 60 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Monorepo

Project-specific patterns for pnpm workspaces + Turborepo.

Architecture Decisions

Workspace Organization

  1. Split apps from packagesapps/ for deployables, packages/ for shared libraries.
  2. Namespace packages — Prefix with @org/ to avoid npm conflicts.
  3. Single lockfilepnpm-lock.yaml at root only. Never commit multiple lockfiles.
  4. No cross-package file access — Never use ../ to reach into other packages; import via dependencies.

Dependency Management

  1. Use workspace:* protocol — Always for internal package dependencies.
  2. Hoist common devDependencies — Shared tooling (TypeScript, ESLint) in root.
  3. Peer dependencies for frameworks — React, Vue, etc. as peers to avoid version conflicts.
  4. Consider Catalogs (pnpm 9.5+) — Centralize versions in pnpm-workspace.yaml for large repos.

Turborepo Tasks

  1. Use ^ for build dependencies"dependsOn": ["^build"] for topological order.
  2. Always define outputs — Without outputs, nothing gets cached.
  3. Mark dev servers as persistent"persistent": true, "cache": false.
  4. Be explicit about environment — List all build-affecting vars in env or globalEnv.

Gotchas

  • Missing outputs in turbo.json silently disables caching for that task. The task runs every time and you won't get an error — just slow builds. Always verify outputs are configured.
  • pnpm install does NOT respect --filter for installation — it always installs the entire workspace. Filtering only works for pnpm run and pnpm exec.
  • workspace:* resolves to the CURRENT version of the local package, not "latest from npm". If the package has "version": "0.0.0", published packages will have "dependency": "0.0.0" — set meaningful versions before publishing.
  • Turborepo's env field in turbo.json uses GLOB patterns, not exact matches. "env": ["API_*"] captures API_KEY, API_URL, etc. Forgetting this causes over-invalidation.
  • turbo run build --filter=app-a builds app-a AND all its workspace dependencies. If a dependency fails, app-a won't build. Check transitive deps.
  • Adding a package to packages/ requires running pnpm install before the workspace recognizes it. The new package also needs a valid package.json with name matching the workspace pattern.
  • TypeScript project references (references in tsconfig.json) must match the workspace dependency graph. Mismatches cause type errors that only appear during tsc --build, not in IDE.
  • turbo.json's globalDependencies invalidates ALL tasks when listed files change. Don't put frequently-changed files here — use task-level inputs instead.
  • Shared Tailwind configs need @source directives pointing to consuming packages' source directories, otherwise classes used in shared packages are purged.
  • pnpm deploy (for production) copies a single package and its dependencies to a target directory. It does NOT run build scripts — build first, then deploy.
  • Remote cache (Vercel or self-hosted) requires outputs to be correct. If outputs are wrong, cached artifacts will be incomplete and downstream tasks break silently.
  • persistent: true tasks prevent turbo run from exiting. Don't include persistent tasks in CI pipelines unless they have a timeout.

Read the full file on GitHub · 60 lines

Files

What ships with it

5 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 60 lines · 132 tokens per session scan A c557279f38a9

Subscribe to this mod's changes

monorepo is a skill published in the GitHub repository avibebuilder/claude-prime (120 stars, last pushed 3mo ago), licensed MIT. It adds 132 tokens to every session and 1,112 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

phx-deps-audit

Audit Hex deps for supply-chain security risk — bidi chars, compile-time exec, maintainer changes, typosquats, CVEs. Use after mix deps.update, when checking if a package upgrade is safe, or reviewing mix.lock PR diffs.

oliver-kriska/claude-elixir-phoenix · 58 tokens

release

CONTRIBUTOR TOOL - Cut a plugin release: bump plugin.json version, finalize CHANGELOG, update README if needed, gate on make ci, commit, tag vX.Y.Z, and create the GitHub release. Use when shipping a new plugin version. NOT distributed.

oliver-kriska/claude-elixir-phoenix · 60 tokens

session-deep-dive

Deep qualitative analysis of high-signal sessions. Spawns subagents with v2 template, synthesizes patterns, compares against known findings. Use after /session-scan.

oliver-kriska/claude-elixir-phoenix · 40 tokens

brainstorm

Brainstorm Elixir/Phoenix features — explore ideas, compare approaches, gather requirements. Use when vague idea, not sure how to approach, or want to discuss before plan.

oliver-kriska/claude-elixir-phoenix · 39 tokens

elixir-idioms

OTP/BEAM patterns and Elixir idioms — GenServer, Supervisor, Task, Registry, pattern matching, with chains, pipes. Use when designing processes or debugging BEAM issues.

oliver-kriska/claude-elixir-phoenix · 44 tokens

security

Enforce Elixir/Phoenix security — auth, OAuth, sessions, CSRF, XSS, SQL injection, input validation, secrets. Use when editing auth files, login flows, RBAC, or API keys.

oliver-kriska/claude-elixir-phoenix · 47 tokens