mysql-debug

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS:技能目的与主要能力基本一致,且数据库访问走官方 mysql CLI 与直连 MySQL,未见明显恶意中转或下载执行链。但其会读取本地明文数据库凭据、将密码直接作为命令行参数传给 mysql,并支持 dev/prod 多环境查询;再加上未验证的 ai-engineering-init 引用与仅文档层面的只读/脱敏约束,使整体更适合判定为中等风险而非恶意。

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Mar 27, 2026, 10:20 AM
Package URL
pkg:socket/skills-sh/xu-cell%2Fai-engineering-init%2Fmysql-debug%2F@4bc056648f43674fb07ba2824e0fc6a4d13cacaa