electricsql

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/write-patterns.md

The fragment shows ordinary database and HTTP application logic with parameterized queries and no evidence of malware or intentional obfuscation. The primary security issue is a likely authorization flaw in the conflict-detection endpoint because its UPDATE lacks a user_id ownership check. Retrying POST requests can also cause duplicate writes when operations are not idempotent. The displayed code should be reviewed and the conflict query should enforce ownership, for example by including user_id = $4 with req.user.id as a parameter.

Confidence: 96%Severity: 62%
AnomalyLOW
references/setup.md

No malware or intentional supply-chain attack behavior is present; this is configuration and usage documentation. The principal risks are insecure deployment examples, hardcoded default credentials, broad PostgreSQL replication privileges, all-table publication, unauthenticated HTTP exposure, and possible leakage through client console logging. These risks are configuration-related rather than malicious code behavior.

Confidence: 99%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:51 AM
Package URL
pkg:socket/skills-sh/oakoss%2Fagent-skills%2Felectricsql%2F@3658e0e00ae07bf8db568393a7239319f2bc8a1988112e487f8416935f85459a
Security Audit — socket — electricsql