neon

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s Neon-management purpose matches its capabilities, and the CLI provenance appears broadly legitimate, but the core data flow is mediated through ClawLink rather than direct Neon APIs. That third-party credential and action brokerage, combined with write-capable infrastructure actions, makes the skill medium risk even without clear malware indicators.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fneon%2F@7d1d53ea89ac52f2d447cbde5741dbd62e965e7c58df8816488ca0688d6861c6
Security Audit — socket — neon