managing-neon
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell scripts utilizing the
neonctlCLI andjqutility to perform resource discovery and metadata analysis on Neon projects, branches, and endpoints. - [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the Neon API (via CLI output) including project names, database owner names, and operation logs. While this creates a standard ingestion surface for external content, the risk is inherent to the database management use case and the skill uses structured parsing with
jqto handle the data. - [SAFE]: The skill incorporates explicit safety rules, such as prioritizing read-only commands (
list,get) and requiring user confirmation for destructive actions likedeleteorreset.
Audit Metadata