azure-deploy

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
references/recipes/azd/sql-managed-identity.md

The code is legitimate Azure SQL managed-identity provisioning documentation, with no clear malware or covert supply-chain behavior. The main security concerns are unsafe `eval` usage and SQL injection risk from inserting unvalidated environment values into SQL identifiers and literals. Validate and allowlist service names, escape SQL identifiers and literals, and avoid `eval` by safely importing environment values. Grant `db_ddladmin` only when migrations genuinely require it.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 17, 2026, 11:19 PM
Package URL
pkg:socket/skills-sh/midudev%2Fautoskills%2Fazure-deploy%2F@0c31efc602706f04ce4f86d14cd8e42e56c1b84d4272f37432cc3924120bfbf1
Security Audit — socket — azure-deploy