exasol-bucketfs

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill coherently matches its purpose of managing Exasol BucketFS via the exapump CLI, with normal capabilities (ls, cp, rm) and configuration-driven access. Primary security concerns center on plaintext credentials in the example config and ensuring TLS validation is enforced. No evident malicious behavior or external data exfiltration patterns are described. Overall risk is moderate (suspicious due to credential storage in plaintext but not actively malicious). Recommended mitigations: enforce strict permissions on ~/.exapump/config.toml, prefer secured secret handling (environment variables, secret managers), and validate input paths to prevent injection.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 03:51 AM
Package URL
pkg:socket/skills-sh/exasol-labs%2Fexasol-agent-skills%2Fexasol-bucketfs%2F@bab2ed65f5f099593be8cf4fd2b5c7b6de7e0eca