dotnet-testing-advanced-webapi-integration-testing

Warn

Audited by Socket on Sep 21, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/database-manager.cs

The code appears to be a legitimate PostgreSQL integration-test fixture, not malware. The primary security issue is SQL injection in SeedProductAsync because the name is interpolated into SQL. The generic raw-SQL methods are also dangerous when reachable with untrusted input, but may be acceptable in a trusted test-only context. Use parameterized NpgsqlCommand parameters for inserted values and restrict or remove arbitrary SQL APIs from production-reachable code.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 21, 2026, 06:41 AM
Package URL
pkg:socket/skills-sh/kevintsengtw%2Fdotnet-testing-agent-skills%2Fdotnet-testing-advanced-webapi-integration-testing%2F@e347bd9930f3c9bac4ca0ba331afd7468b60e28060bb4e1e7bca05f2246844b2
Security Audit — socket — dotnet-testing-advanced-webapi-integration-testing