querypie
Warn
Audited by Socket on Jul 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s database-query purpose is coherent, and its commands align with QueryPie access, but its trust model is weak: it auto-installs and uses an external CLI from a personal GitHub repo via curl|sh, then relies on that binary to handle authentication sessions and database access. I do not see confirmed malicious behavior or off-purpose data exfiltration, but the install source and credential delegation are higher-risk than necessary.
Confidence: 86%Severity: 80%
Audit Metadata