opencode-session-db

Warn

Audited by Socket on Sep 28, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/query.sh

The code appears to be a legitimate read-only SQLite inspection and export script, with no evident malware or supply-chain backdoor behavior. Its primary security weakness is SQL injection caused by direct interpolation of command-line arguments into SQL. Parameterized queries or strict validation of session IDs, search terms, and numeric limits should be used. The script also intentionally exposes sensitive local conversation and tool data to its caller.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 28, 2026, 11:50 AM
Package URL
pkg:socket/skills-sh/dzianisv%2Fopencode-plugins%2Fopencode-session-db%2F@f948de8438b409457cf9041ce82bb64eccf561aa2d70fef78a4c4080f484d9dc
Security Audit — socket — opencode-session-db