Versioned security assessment

Report ID: SA-8B5AD159

9/28/2026, 4:22:06 PM

turbo-pipelines security assessment v1

Skill Security Certification Report

Audit History
Scanner version 3.0.0 Audit model: codex Latest published report
Skill name
turbo-pipelines
Version
v1
Maintainer
goldsky-io
Coverage
16 Files scanned · 1,477 Lines analyzed
Policy version
skillstore-security-audit-policy-v1

Highest confirmed finding severity

Critical

7 confirmed security findings require attention.

Installation context

Check the current Skill page

This page summarizes report evidence only. The Skill page provides the canonical install advisory.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

Most static matches are documentation false positives involving Markdown syntax, URLs, field names, and a targeted troubleshooting path. The installer examples that pipe remote content directly to a shell are confirmed critical risks and require removal or a verified installation process.

Report position

Latest published report

Latest refers to the report sequence, not to artifact currentness.

Audit attestation

Active attestation

A public attestation is available for this exact report.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

16 Files scanned · 1,477 Lines analyzed

7 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Commit and path bound

  2. Artifact

    Content and tree hashes bound

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Observed in 11 evidence locations

Filesystem access

May read or write local files.

Observed in 1 evidence location

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Observed in 50 evidence locations

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (7)

RISK-001 Critical
Pipe to shell pattern
curl https://install-turbo.goldsky.com | sh
The documented command downloads remote content and pipes it directly to a shell. A compromised endpoint or intercepted response could execute arbitrary commands with the user's privileges.
RISK-002 Critical
Pipe to shell pattern
curl https://install-turbo.goldsky.com | sh
The documented command downloads remote content and pipes it directly to a shell. A compromised endpoint or intercepted response could execute arbitrary commands with the user's privileges.
RISK-003 Critical
Pipe to shell pattern
| **Turbo binary not installed** | Run `curl https://install-turbo.goldsky.com \| sh`
The documented command downloads remote content and pipes it directly to a shell. A compromised endpoint or intercepted response could execute arbitrary commands with the user's privileges.
RISK-004 Critical
Pipe to shell pattern
- **Goldsky CLI** — `curl https://goldsky.com | sh`
The documented command downloads remote content and pipes it directly to a shell. A compromised endpoint or intercepted response could execute arbitrary commands with the user's privileges.
RISK-005 Critical
Pipe to shell pattern
- **Turbo extension** (separate binary) — `curl https://install-turbo.goldsky.com | sh`
The documented command downloads remote content and pipes it directly to a shell. A compromised endpoint or intercepted response could execute arbitrary commands with the user's privileges.
RISK-006 Critical
Pipe to shell pattern
| Install Goldsky CLI | `curl https://goldsky.com \| sh` |
The documented command downloads remote content and pipes it directly to a shell. A compromised endpoint or intercepted response could execute arbitrary commands with the user's privileges.
RISK-007 Critical
Pipe to shell pattern
| Install Turbo extension | `curl https://install-turbo.goldsky.com \| sh` |
The documented command downloads remote content and pipes it directly to a shell. A compromised endpoint or intercepted response could execute arbitrary commands with the user's privileges.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    Critical
    Remote installer commands pipe downloaded content directly to a shell.
    Replace curl-to-shell examples with a verified package or release workflow. Require HTTPS, checksum or signature verification, and a reviewable local installer before execution.
  2. FIX-002
    High
    The installation guidance does not show provenance or integrity verification.
    Link to the official release page and document the expected checksum or signature for each binary version.
  3. FIX-003
    Low
    The troubleshooting command deletes a hidden executable in the user's home directory.
    Prefer an official uninstall or upgrade command, and require confirmation before removing the existing binary.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
8b5ad1599e7c55e9b6c627bca3f556f6e9061cb1
Content hash
3ff2674b96283c041e6508ffc0c1447fd4f76b5a4a74b4cb82d760ad3aca8ae4
Tree hash
4aaf1cba05189cead04306b7207defba37c1dd745d976ec27926749215fe65a2
Skill path
skills/goldsky-io/turbo-pipelines
Audit payload hash
f6d3bb961bbdc6e1e5cf02062172990c

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: active