azure-cosmos-db-py
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyassets/cosmos_client_template.py
LOWAnomalyLOW
assets/cosmos_client_template.py
This is a Cosmos DB persistence helper with no clear evidence of intentional malware or supply-chain sabotage. The primary security issue is a potential Cosmos SQL injection caused by direct concatenation of caller-controlled extra_filter. The unused upsert partition_key is a separate authorization and data-integrity concern, especially in multi-tenant applications. TLS verification is disabled only for endpoints identified as local emulator addresses and is not inherently malicious. The fragment is incomplete or syntactically truncated at the end.
Confidence: 97%Severity: 62%
Audit Metadata