read-only-postgres

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent, intentionally narrow tool for safe read-only PostgreSQL exploration. Its footprint—reading a local credentials file, establishing read-only DB connections, and returning query results—matches the stated purpose. The main security considerations are plaintext storage of credentials (mitigated by file permissions but not mitigated by secret-management integration) and potential exposure of sensitive data through query output if not properly access-controlled. Overall, the risk is low-to-moderate (benign with notable caution around credential handling), and no evidence of exfiltration, autonomous actions, or supply-chain issues. Recommend acceptance with explicit guidance to integrate secret management, enforce strict access controls, and consider masking or redacting sensitive columns by default when displaying results.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 02:27 AM
Package URL
pkg:socket/skills-sh/jawwadfirdousi%2Fagent-skills%2Fread-only-postgres%2F@02a2349775dd3702577943d8c898a549ffc4cb37