puda-database

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated purpose matches database querying, but it relies on an unverifiable local `puda` CLI with no confirmed provenance or install path. There is no direct exfiltration signal, yet the required opaque executable and arbitrary SQL execution create high security risk.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 14, 2026, 08:02 AM
Package URL
pkg:socket/skills-sh/PUDAP%2Fskills%2Fpuda-database%2F@e0966f681ff0ce702f09f68d90865f1d6ff79052