turnstile-spin

Warn

Audited by Socket on Sep 13, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/persist-skill.sh

No direct malicious behavior is evident in this script itself (no credential access, exfiltration, reverse shells, or hidden execution). However, it is a network-and-supply-chain-sensitive installer: it uses `npx --yes degit` (unpinned/unverified npm tool) to fetch/extract remote GitHub repository content into a user-controlled directory and then marks fetched `scripts/*.sh` as executable. If the npm package resolution or upstream repository content is compromised, this module will persist and enable potentially harmful scripts for later execution by other components. Use pinning/integrity verification and consider execution/sandbox controls for fetched scripts.

Confidence: 74%Severity: 55%
Audit Metadata
Analyzed At
Sep 13, 2026, 03:58 PM
Package URL
pkg:socket/skills-sh/celeroncoder%2Fskills%2Fturnstile-spin%2F@9e1654e5a0276d4c5b0fe96d605677e1ef75365518f8b4f549a60cebb8b02b01
Security Audit — socket — turnstile-spin