cloudflare-hyperdrive

skills-sh:jezweb_claude-skills__cloudflare-hyperdrive

View source
D
40/100

First Seen

Feb 18, 2026

Last Scanned

Feb 20, 2026

Findings

5

Score

40/100

HIGH 4
LOW 1

Findings (5)

HIGH
Database connection string
L384

Detects database connection strings with credentials

postgres://user:password@192.168.1.100:
FIX

Remove the database connection string and replace it with an environment variable reference. Rotate the database password if the connection string was exposed publicly.

FP?

Likely FP if the connection string uses localhost with no password (e.g., mongodb://localhost:27017/mydb) or is a documented example URI.

HIGH
Database connection string
L389

Detects database connection strings with credentials

postgres://user:password@db.example.com:
FIX

Remove the database connection string and replace it with an environment variable reference. Rotate the database password if the connection string was exposed publicly.

FP?

Likely FP if the connection string uses localhost with no password (e.g., mongodb://localhost:27017/mydb) or is a documented example URI.

HIGH
Database connection string
L790

Detects database connection strings with credentials

postgres://user:password@db.projectref.supabase.co:
FIX

Remove the database connection string and replace it with an environment variable reference. Rotate the database password if the connection string was exposed publicly.

FP?

Likely FP if the connection string uses localhost with no password (e.g., mongodb://localhost:27017/mydb) or is a documented example URI.

HIGH
Database connection string
L1549

Detects database connection strings with credentials

postgres://user:password@db.example.com:
FIX

Remove the database connection string and replace it with an environment variable reference. Rotate the database password if the connection string was exposed publicly.

FP?

Likely FP if the connection string uses localhost with no password (e.g., mongodb://localhost:27017/mydb) or is a documented example URI.

LOW
System package manager install
L1536

Detects system-level package installation via brew, apt, yum, or dnf

brew install c
FIX

Pin system packages to specific versions where the package manager supports it. Document the exact packages required and prefer containerized environments to avoid system-wide changes.

FP?

Likely FP if the match is standard setup documentation listing well-known system packages (e.g., apt install git curl) that are prerequisites.