Postgres MCP Pro Server for Database Analysis and Tuning

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS due to transitive skill installation and source/distribution mismatch: users are told the skill is sourced from `crystaldba/postgres-mcp`, but the actual install target is the separate `agentskillexchange/skills` repo. That is a medium supply-chain risk and trust-chain issue, but there is no direct evidence in the provided text of credential theft, covert exfiltration, or behavior fundamentally incompatible with a PostgreSQL analysis skill.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:39 AM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fpostgres-mcp-pro-server-for-database-analysis-and-tuning%2F@bbc95e11aa9a8233cd304431d0404de5fe3f7608
Security Audit — socket — Postgres MCP Pro Server for Database Analysis and Tuning