sql-planner

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Anomaly
AnomalyLOW
new-connector/SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it creates a high-risk connector pattern by persisting remote DB command templates and relying on raw {sql} shell injection at runtime. Main concerns are command-injection potential and plaintext credential storage, not overt malware or deceptive supply-chain behavior.

Confidence: 84%Severity: 69%
Audit Metadata
Analyzed At
Mar 30, 2026, 01:57 PM
Package URL
pkg:socket/skills-sh/wilmanbarrios%2Fskills%2Fsql-planner%2F@1cbc91b72f898681bdce17693da414697c47b05f