turso-best-practices

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This file is a benign documentation/best-practices guide for Turso/libSQL. I found no evidence of intentionally malicious code, obfuscation, or active exfiltration. The main security concerns are operational: the recommended pipe-to-shell installer, unpinned third-party installs, and example patterns that could lead to credential leakage or production-data sprawl into development environments. Mitigations: avoid curl|bash installers (or verify signatures/checksums), pin package versions and use verified package sources, never hardcode tokens in repos, scope CI secrets minimally, and treat production dumps as sensitive data.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 06:58 PM
Package URL
pkg:socket/skills-sh/futuregerald%2Ffuturegerald-claude-plugin%2Fturso-best-practices%2F@3ff587765dc660138051a1d8fade9e734a275a45