mssql-cli

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The mssql-cli skill aligns with its stated purpose of querying SQL Server databases by parsing connection strings into CLI flags and orchestrating query execution via standard CLI tools. The main security considerations are credential handling (passwords on the CLI, potential exposure in logs or process listings) and reliance on external binaries not controlled by the skill. There are no evident data exfiltration pathways or unauthorized network calls. Overall, the footprint is coherent for a developer tooling helper, but the credential handling pattern warrants best-practice mitigation (prefer env vars or interactive prompts, ensure redaction, document secure usage).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 11:18 PM
Package URL
pkg:socket/skills-sh/arisng%2Fgithub-copilot-fc%2Fmssql-cli%2F@740854db46badab90fefd708ae2574e6220c532b