update-turbo

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches updating Turbo, but the mechanism is overly trusting. It fetches mutable instructions from whatever remote is configured locally and tells the agent to execute them without verifying publisher, domain, tag, commit, or integrity, creating a strong supply-chain and remote-instruction risk.

Confidence: 89%Severity: 83%
Audit Metadata
Analyzed At
Apr 18, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/tobihagemann%2Fturbo%2Fupdate-turbo%2F@da4d6c00af811af4c14398e18d1a105f828f565f