clickhouse-pydantic-config

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Functionally this skill does what it claims: map env-configured ClickHouse connection data into a DBeaver data-sources.json using a Pydantic model. The primary security issue is credential handling: cloud mode writes plaintext credentials into a local JSON file, increasing the chance of accidental exposure (git commits, CI artifacts, backups). There is also a transitive trust risk from the companion credential-retrieval skill. No evidence of intentional malicious code, network exfiltration, or obfuscation is present in the provided materials. Recommended actions: enforce .dbeaver/ in .gitignore (and verify before generating), restrict generated-file permissions, prefer OS keyrings or DBeaver native credential storage over writing plaintext, avoid generating credentials in CI, and audit/pin any external skills that retrieve secrets.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 28, 2026, 03:58 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fclickhouse-pydantic-config%2F@2d1bbf753f2f83e8a38b90810a828b936edce86d