PostgreSQL MCP Server

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the PostgreSQL access purpose is coherent, but the install and trust model are not fully aligned with the claimed source. The main risk is transitive installation of a third-party-hosted skill through `npx skills add`, which gives externally supplied instructions the agent's permissions without clear same-org provenance. No direct credential theft or overt malicious behavior is shown, so this is better classified as medium/high security risk rather than confirmed malware.

Confidence: 88%Severity: 71%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:40 AM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fpostgresql-mcp-server%2F@10858dbda4ee0c72c693a356cae21893dff6edb8