sql-injection-detector

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the content is mostly generic documentation, but it grants broad Bash(npm:*) execution that is not clearly necessary for the minimal stated purpose. No direct malware, credential theft, or exfiltration is evident, yet the combination of a security-testing theme and wildcard npm execution makes the skill higher risk than its sparse description justifies.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
May 4, 2026, 02:30 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fsql-injection-detector%2F@a61626e6af122725707abc40a2a238bfaa2f73f7