Postgres MCP Pro

Warn

Audited by Socket on Aug 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core Postgres analysis capability is coherent and the upstream Docker/PyPI distribution looks consistent with the stated project, so this is not fundamentally malicious. The main concern is the third-party, unpinned skill-install path and the fact that database credentials are handed to an installed MCP server that can perform write actions in some modes.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
Aug 14, 2026, 09:04 AM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fpostgres-mcp-pro%2F@8190d0715f5a475acec9901ac71ef1a125a39677
Security Audit — socket — Postgres MCP Pro