mssql-tools

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is coherently aligned with its stated purpose of providing MSSQL database tooling via Python, including connection testing, table/schema inspection, and query execution. It uses standard dependencies (pymssql) from a well-known registry and standard platform prerequisites. However, credential handling via command-line passwords and the ability to run arbitrary SQL introduce meaningful security risks, particularly around credential exposure and data exfiltration in untrusted contexts. The data flow is straightforward and appropriate for the用途, but mitigations (secure password handling, input validation to prevent SQL injection, principle of least privilege, and explicit data-handling policies) are advisable before broad deployment.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 03:27 AM
Package URL
pkg:socket/skills-sh/huangzt%2Fmy-agent-skills%2Fmssql-tools%2F@15f9a8a734ea8daf946c72de4ca7efcff4be2c97