constructive-graphql-codegen

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill's documentation and configuration are coherent with its stated purpose (schema export and code generation). The main security concerns are supply-chain and credential risks associated with PGPM module deployment and ephemeral database provisioning, plus forwarding of Authorization tokens and headers to user-specified endpoints. These behaviors are expected for a tool that introspects databases and endpoints, but they require careful handling: only run against trusted modules/endpoints, avoid using production credentials for introspection, and review any PGPM module code before allowing the generator to deploy it. No explicit malicious code or obfuscated payloads are present in the provided documentation, but capabilities that execute or build third-party module code and that accept raw DB credentials raise moderate supply-chain risk.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 08:22 AM
Package URL
pkg:socket/skills-sh/constructive-io%2Fconstructive-skills%2Fconstructive-graphql-codegen%2F@125d6167a705a1b360301378899c4141342d75a4