turnstile-spin
Warn
Audited by Socket on Sep 13, 2026
1 alert found:
AnomalyAnomalyscripts/persist-skill.sh
LOWAnomalyLOW
scripts/persist-skill.sh
No direct malicious behavior is evident in this script itself (no credential access, exfiltration, reverse shells, or hidden execution). However, it is a network-and-supply-chain-sensitive installer: it uses `npx --yes degit` (unpinned/unverified npm tool) to fetch/extract remote GitHub repository content into a user-controlled directory and then marks fetched `scripts/*.sh` as executable. If the npm package resolution or upstream repository content is compromised, this module will persist and enable potentially harmful scripts for later execution by other components. Use pinning/integrity verification and consider execution/sandbox controls for fetched scripts.
Confidence: 74%Severity: 55%
Audit Metadata