cloud-sql-sqlserver-monitor

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/get_system_metrics.js

No direct malicious payload is evident within this wrapper file (no obfuscation, no explicit exfiltration, no persistence). However, it dynamically executes an external npm tool via npx and forwards an augmented environment to that executed code. When GEMINI_CLI==='1', it also reads a local '../../../.env' and merges its contents into the child process environment, creating a realistic risk of unintentional secret/config exposure to the downstream tool. Review and audit the invoked '@toolbox-sdk/server' and the 'get_system_metrics' implementation, and avoid passing .env secrets into untrusted or externally executed components unless strictly necessary.

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:19 AM
Package URL
pkg:socket/skills-sh/gemini-cli-extensions%2Fcloud-sql-sqlserver%2Fcloud-sql-sqlserver-monitor%2F@cc0a9a11eebaafa1e440ce3924d05ca13bd7106b