Postgres MCP Pro
Warn
Audited by Socket on Aug 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core Postgres analysis capability is coherent and the upstream Docker/PyPI distribution looks consistent with the stated project, so this is not fundamentally malicious. The main concern is the third-party, unpinned skill-install path and the fact that database credentials are handed to an installed MCP server that can perform write actions in some modes.
Confidence: 85%Severity: 62%
Audit Metadata