NYC

surrealdb-expert

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This is an instructional SurrealDB skill focused on secure design and best practices. I found no intentionally malicious code or hidden exfiltration. The main risks are operational: hard-coded example credentials in tests, and unsafe example snippets (clearly labeled) that could be copy-pasted into production. The guidance about CVEs highlights real server-side risks that must be mitigated by keeping SurrealDB patched. Overall the content is coherent with its stated purpose but care is required when using example credentials and running performance tests against non-test instances.

Confidence: 80%Severity: 35%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:21 PM
Package URL
pkg:socket/skills-sh/martinholovsky%2Fclaude-skills-generator%2Fsurrealdb-expert%2F@280854124b4e5e7e143b3fabef3653242fcf8a8d