dbt-test

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior is mostly coherent with a dbt testing assistant: it reads dbt metadata, edits schema YAML, validates SQL, and runs test/build commands. The main issue is install/execution trust: the skill depends on the externally executed `altimate-dbt` binary without providing a clearly verifiable official install path, version pin, or integrity mechanism in the available evidence. There is no strong sign of credential harvesting, disproportionate permissions, or malicious data routing, but the unverifiable external CLI keeps overall risk elevated.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Apr 21, 2026, 04:42 AM
Package URL
pkg:socket/skills-sh/AltimateAI%2Faltimate-code%2Fdbt-test%2F@dd93aa9855e81f713a42f55dde0d7755409c8127