turso

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/multi-tenant.md

The fragment is legitimate multi-tenant provisioning and migration documentation with no clear malware or supply-chain backdoor indicators. It presents meaningful security risks if used unchanged: unvalidated tenant identifiers, possible cross-tenant access, use of a broad organization token for database access, potentially overbroad read_attach permissions, and execution of arbitrary SQL across all tenant databases. Tenant identity must be authorized independently of URL construction, identifiers should be validated and encoded, database tokens should be least-privileged and scoped, and migration input must be trusted and controlled.

Confidence: 97%Severity: 67%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:53 AM
Package URL
pkg:socket/skills-sh/oakoss%2Fagent-skills%2Fturso%2F@3b662677fd9526667d06418c745882449212b03bd2743a7769d47ab22f774dc3
Security Audit — socket — turso