update-turbo
Warn
Audited by Socket on Apr 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches updating Turbo, but the mechanism is overly trusting. It fetches mutable instructions from whatever remote is configured locally and tells the agent to execute them without verifying publisher, domain, tag, commit, or integrity, creating a strong supply-chain and remote-instruction risk.
Confidence: 89%Severity: 83%
Audit Metadata