skills/ericrisco/rsc-harness/neon/Gen Agent Trust Hub

neon

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected in the skill instructions or associated scripts.
  • [EXTERNAL_DOWNLOADS]: The skill recommends standard integration tools for the Neon platform, including the @neondatabase/serverless driver and the neonctl CLI. These are official resources for the platform and are presented in a neutral, informative context for development purposes.
  • [COMMAND_EXECUTION]: The scripts/verify.sh utility performs static analysis on local project files to identify potential performance issues or resource leaks (e.g., module-scope connection pooling). The script uses standard system tools like find and grep in a read-only capacity and lacks network or persistence capabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes an attack surface through its ability to ingest and analyze user-controlled source code files.
  • Ingestion points: Source code and environment files (.js, .ts, .env) processed by scripts/verify.sh.
  • Boundary markers: Not applicable; the script uses grep-based pattern matching rather than complex parsing.
  • Capability inventory: Limited to local filesystem reads and console output within the shell environment.
  • Sanitization: The script performs literal matches and does not execute or evaluate the content of the scanned files, mitigating common injection vectors.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:10 PM
Security Audit — agent-trust-hub — neon