databricks-python-sdk

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/4-unity-catalog.py

This code fragment is best characterized as a high-privilege Databricks administrative automation script that enumerates and manages Unity Catalog/Volumes and performs file upload/download/delete via Databricks Volumes. It contains no clear supply-chain malware signals (no obfuscation, no exec/subprocess, no secret harvesting, no suspicious external network destinations), but it does include substantial operational danger: broad create/update/delete operations, destructive deletes (catalog/schema/table/volume/file), hardcoded identifiers/ownership values, and overwrite=True for uploads. The file transfer capabilities could be used for data exfiltration or disruption if run with privileged credentials or in the wrong environment. The provided snippet also appears truncated near the final delete call, slightly reducing assessment confidence.

Confidence: 60%Severity: 55%
Audit Metadata
Analyzed At
Aug 11, 2026, 02:53 PM
Package URL
pkg:socket/skills-sh/databricks-solutions%2Flakebase-online-ml%2Fdatabricks-python-sdk%2F@aae49a3ee3aaeb160f5dc969d389ae3898937e5f7b45d00ae21eca126103e8e8
Security Audit — socket — databricks-python-sdk