smart-query

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/query.py

No explicit malware indicators (no obfuscation, no subprocess/network activity, no persistence or covert exfiltration) are present in this snippet. However, it functions as an unrestricted SQL execution CLI: it executes arbitrary user-provided SQL via `cursor.execute(sql)` and commits for non-read statements, then prints full results or raw exception details to stdout. This creates a strong risk of data exposure and unauthorized data modification/destruction if the CLI arguments or runtime environment are not strictly controlled.

Confidence: 70%Severity: 85%
Audit Metadata
Analyzed At
Sep 15, 2026, 06:24 AM
Package URL
pkg:socket/skills-sh/zrt-ai-lab%2Fopencode-skills%2Fsmart-query%2F@aab01cf4b20b6017942e7ff379120093fad6e039ff3f1283ea929cbd07c9d3fd
Security Audit — socket — smart-query