sqlserver-expert

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Credential file access detected This skill/documentation is benign and aligned with its stated purpose (SQL Server expert guidance and Node.js mssql examples). There are no signs of credential exfiltration, obfuscated malicious code, or third-party proxying of credentials. The main security note: config.options.trustServerCertificate is set to true — this weakens TLS verification and should not be used in untrusted networks or production. Also avoid SELECT * in production and ensure proper pooling concurrency handling as appropriate. LLM verification: The sqlserver-expert fragment is coherent with its stated purpose, demonstrating proper parameterized query usage, environment-based credential handling, and common T-SQL examples. The credential-file-access finding is likely a false positive. Minor production considerations include tightening trustServerCertificate and encryption settings for deployment. Overall, the footprint is benign and appropriate for its described use-case.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:40 PM
Package URL
pkg:socket/skills-sh/fabriciofs%2Fmcp-sql-server%2Fsqlserver-expert%2F@35fa94df03f78ab9d5a304b6ff15ccb805986881