data-analysis

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/analyze.py

No definitive evidence of overt malicious behavior (e.g., keylogging, credential theft, explicit exfiltration, or a hidden backdoor) is visible in the provided fragment. However, the module contains multiple high-risk security/supply-chain patterns: it can install Python packages at runtime via pip when imports fail, it installs/loads a DuckDB extension at runtime (INSTALL/LOAD spatial), and it constructs/executes dynamic SQL using untrusted inputs (file paths and Excel sheet names) plus a dedicated mode that likely executes user-supplied SQL. This combination warrants security review and hardening (disable runtime installs/extension loading by default, pin/verify dependencies, and parameterize/escape SQL or restrict query execution).

Confidence: 60%Severity: 72%
Audit Metadata
Analyzed At
Aug 19, 2026, 05:30 PM
Package URL
pkg:socket/skills-sh/hk-hub%2Fagentskills%2Fdata-analysis%2F@13166200821f22b395f62edeee53fb4474f128ede018ac73d4e7844b5bc247dc
Security Audit — socket — data-analysis