civitai-analyst

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's functionality (NL→SQL analytics for Civitai videos) is legitimate and useful, but the current specification lacks critical security controls. The main risks are SQL injection and information leakage via raw error messages, unconstrained SQL execution, and exposure of internal IDs/PII in reports or logs. No explicit signs of malware or obfuscation appear in the provided text, but the ability to synthesize and execute arbitrary SQL from user input makes deployment without hardened controls potentially dangerous. Implement parameterized queries, least-privilege DB roles, template allowlists, error sanitization, and output redaction before enabling execution in production.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 03:43 AM
Package URL
pkg:socket/skills-sh/feed-mob%2Fagent-skills%2Fcivitai-analyst%2F@7c349f55aeee5b47b712c225c0cac07039c8161a