flowerpower

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill documentation and example code are consistent with the stated purpose (lightweight data pipelines). I found no explicit malicious behavior or supply-chain download-execute patterns. The primary security concerns are operational: use of fsspec/S3 requires secure credential management, and there is a direct SQL SELECT built via f-string (get_last_watermark) which could allow SQL injection if table_name is untrusted. No evidence of obfuscation or credential exfiltration. Recommend hardening examples by parameterizing/whitelisting table names, demonstrating secure credential practices, and avoiding direct string interpolation into SQL.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 03:21 PM
Package URL
pkg:socket/skills-sh/legout%2Fdata-agent-skills%2Fflowerpower%2F@c3dbf1fe62abc027f002da8d3b9154931849b83c