altinity-expert-clickhouse-connection

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s database-diagnostic behavior is largely aligned with its stated purpose and `clickhouse-client` use is normal, but the instruction to use any MCP server with 'clickhouse' in the name creates avoidable trust and credential-forwarding risk. Risk is medium rather than high because there is no explicit exfiltration endpoint, no malicious payload, and official same-org ClickHouse/Altinity MCP options do exist.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
May 12, 2026, 07:22 PM
Package URL
pkg:socket/skills-sh/Altinity%2Faltinity-skills%2Faltinity-expert-clickhouse-connection%2F@61239db5ff375121cc92e4775ddedd094577de3e
Security Audit — socket — altinity-expert-clickhouse-connection