Postgres MCP Pro Server for Database Analysis and Tuning
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS due to transitive skill installation and source/distribution mismatch: users are told the skill is sourced from `crystaldba/postgres-mcp`, but the actual install target is the separate `agentskillexchange/skills` repo. That is a medium supply-chain risk and trust-chain issue, but there is no direct evidence in the provided text of credential theft, covert exfiltration, or behavior fundamentally incompatible with a PostgreSQL analysis skill.
Confidence: 84%Severity: 58%
Audit Metadata