prompt-registry-patterns

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill design is coherent with its stated purpose of versioned prompt management and governance. The primary security concern is an explicit SQL injection risk in the Quick Loading Pattern due to unsanitized prompt_key interpolation in a SELECT statement. This is a concrete data-flow risk that could undermine the integrity of the prompt registry if exploited. Other risks are moderate and mostly tied to proper access controls and safe handling of prompts. Treat as SUSPICIOUS due to the concrete SQL injection vector; mitigate by parameterizing queries or escaping inputs and reviewing all runtime load paths. No external download/install supply-chain risk identified in the provided fragments, and no credential exfiltration patterns are evident beyond standard platform authentication.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:35 AM
Package URL
pkg:socket/skills-sh/databricks-solutions%2Fvibe-coding-workshop-template%2Fprompt-registry-patterns%2F@637f47afdaf42cdce1ccdaee61d3ac4498060576