managing-neon

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell scripts utilizing the neonctl CLI and jq utility to perform resource discovery and metadata analysis on Neon projects, branches, and endpoints.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the Neon API (via CLI output) including project names, database owner names, and operation logs. While this creates a standard ingestion surface for external content, the risk is inherent to the database management use case and the skill uses structured parsing with jq to handle the data.
  • [SAFE]: The skill incorporates explicit safety rules, such as prioritizing read-only commands (list, get) and requiring user confirmation for destructive actions like delete or reset.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:28 AM
Security Audit — agent-trust-hub — managing-neon