database-schema-designer

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/schema-design-and-security.md

This fragment appears to be legitimate multi-tenant schema and RLS code, not malware or an intentional supply-chain attack. It contains a significant security risk: the separate permissive tasks_hide_deleted policy does not combine with the workspace policy as an AND condition, so authorized users may be able to read soft-deleted tasks. Combine the conditions in one policy or use restrictive policy semantics, and ensure app_user cannot bypass RLS and that the session identity is securely established.

Confidence: 97%Severity: 68%
Audit Metadata
Analyzed At
Sep 16, 2026, 08:05 AM
Package URL
pkg:socket/skills-sh/borghei%2Fclaude-skills%2Fdatabase-schema-designer%2F@1e202e067ee9a59030ecded1aa7d487767b44ec63605a642248223b8c1453781
Security Audit — socket — database-schema-designer