turso

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
references/quickstart.md

The remote installer pattern (curl | sh / irm | iex) represents a classic high-supply-chain-risk vector due to unverified remote code execution. To reduce risk, prefer: pinned, signed releases; checksums or signature verification; explicit installer provenance; use of package managers or container/VM images with verifiable hashes; and offline or CI-verified installation methods. Implement security controls around installer delivery, such as TLS pinning, content hashing, and code signing.

Confidence: 65%Severity: 66%
Audit Metadata
Analyzed At
Apr 21, 2026, 12:21 AM
Package URL
pkg:socket/skills-sh/itechmeat%2Fllm-code%2Fturso%2F@11e08c065d2c2481b49538e45afb9b290ae95502