database-security

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
references/compliance-frameworks.md

No apparent malicious code or supply-chain payload is present. The fragment is legitimate compliance-oriented SQL documentation, but it contains significant security design issues: unauthenticated or insufficiently authorized SECURITY DEFINER data deletion/export functions, missing fixed search_path hardening, potentially excessive whole-row data export, and an invalid PostgreSQL SELECT audit trigger. These issues could enable unauthorized data access or leave PHI access unaudited if implemented as written.

Confidence: 96%Severity: 72%
AnomalyLOW
references/zero-trust-database.md

The fragment is defensive security architecture documentation and shows no evidence of malware or intentional sabotage. The primary security concern is the SECURITY DEFINER JIT-grant function: without explicit caller authorization, bounded duration validation, a hardened search_path, protected table ownership, and audit logging, it could enable unauthorized or overly long administrative access. The examples should be treated as incomplete until those controls are implemented.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:52 AM
Package URL
pkg:socket/skills-sh/oakoss%2Fagent-skills%2Fdatabase-security%2F@690435e29dd66c02016c1265fdb2c9434043a0f371018e21ff55f8b776e2419c
Security Audit — socket — database-security