skills/kevintsengtw/dotnet-testing-agent-skills/dotnet-testing-advanced-webapi-integration-testing/Socket
dotnet-testing-advanced-webapi-integration-testing
Warn
Audited by Socket on Sep 21, 2026
1 alert found:
AnomalyAnomalytemplates/database-manager.cs
LOWAnomalyLOW
templates/database-manager.cs
The code appears to be a legitimate PostgreSQL integration-test fixture, not malware. The primary security issue is SQL injection in SeedProductAsync because the name is interpolated into SQL. The generic raw-SQL methods are also dangerous when reachable with untrusted input, but may be acceptable in a trusted test-only context. Use parameterized NpgsqlCommand parameters for inserted values and restrict or remove arbitrary SQL APIs from production-reachable code.
Confidence: 98%Severity: 58%
Audit Metadata