dbt-migration-ms-sql-server

Fail

Audited by Socket on Mar 13, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
translation-references/transact-built-in-procedures.md

The procedure is not an obvious backdoor or malware, but it constructs and executes SQL by concatenating caller-supplied inputs without escaping or validation. This makes it vulnerable to SQL/statement injection (via value and identifier parameters) and fragile due to inconsistent NULL/empty handling. Recommended: do not deploy this as-is in environments where callers may supply untrusted input; harden by input validation, identifier quoting/escaping, and escaping of literal values before EXECUTE IMMEDIATE.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 13, 2026, 09:51 PM
Package URL
pkg:socket/skills-sh/sfc-gh-dflippo%2Fsnowflake-dbt-demo%2Fdbt-migration-ms-sql-server%2F@3f64f8d5c002ddb59f68973d2884af20f2de213d