configuring-imports
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyreferences/schemas/rdbms.yml
LOWAnomalyLOW
references/schemas/rdbms.yml
This fragment is a declarative RDBMS import configuration schema, not apparent malware. It exposes legitimate but high-impact capabilities for executing user-defined SQL and bulk database operations. The principal risk is SQL injection or unintended database writes if query templates, identifiers, merge SQL, or Handlebars-rendered values are controlled by untrusted parties and are executed without parameterization and strict validation. No evidence of supply-chain malware or unauthorized system activity is present in the shown code.
Confidence: 94%Severity: 62%
Audit Metadata