smart-query
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecurityscripts/query.py
MEDIUMSecurityMEDIUM
scripts/query.py
No explicit malware indicators (no obfuscation, no subprocess/network activity, no persistence or covert exfiltration) are present in this snippet. However, it functions as an unrestricted SQL execution CLI: it executes arbitrary user-provided SQL via `cursor.execute(sql)` and commits for non-read statements, then prints full results or raw exception details to stdout. This creates a strong risk of data exposure and unauthorized data modification/destruction if the CLI arguments or runtime environment are not strictly controlled.
Confidence: 70%Severity: 85%
Audit Metadata