azure-cosmos-db-py

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/cosmos_client_template.py

This is a Cosmos DB persistence helper with no clear evidence of intentional malware or supply-chain sabotage. The primary security issue is a potential Cosmos SQL injection caused by direct concatenation of caller-controlled extra_filter. The unused upsert partition_key is a separate authorization and data-integrity concern, especially in multi-tenant applications. TLS verification is disabled only for endpoints identified as local emulator addresses and is not inherently malicious. The fragment is incomplete or syntactically truncated at the end.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 12:19 PM
Package URL
pkg:socket/skills-sh/microsoft%2Fskills%2Fazure-cosmos-db-py%2F@73b1630e52164d161dc877a79411bbd857f278c5fd6afbac4263c97a3de1dd3d
Security Audit — socket — azure-cosmos-db-py