sql-expert

Warn

Audited by Socket on Oct 2, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/sql_helper.py

No clear indicators of intentional malware (exfiltration/backdoor/credential theft) are present in the provided fragment. However, the module is security-relevant: it executes caller-provided SQL directly and interpolates table/column identifiers into SQL strings without quoting/validation, creating substantial SQL injection risk when any identifiers or SQL strings are attacker-influenced. Additionally, the fragment appears corrupted/incomplete (documentation text embedded where code should be, and undefined references in __main__), increasing the likelihood that real behavior differs from the snippet and should be re-audited against the actual published package.

Confidence: 46%Severity: 58%
Audit Metadata
Analyzed At
Oct 2, 2026, 06:47 AM
Package URL
pkg:socket/skills-sh/autumnsgrove%2Fclaudeskills%2Fsql-expert%2F@707f1c8747dc9cee7ecf833ff5e9669ee46ade619ca5459baae41cd996b992f4
Security Audit — socket — sql-expert