neon
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected in the skill instructions or associated scripts.
- [EXTERNAL_DOWNLOADS]: The skill recommends standard integration tools for the Neon platform, including the
@neondatabase/serverlessdriver and theneonctlCLI. These are official resources for the platform and are presented in a neutral, informative context for development purposes. - [COMMAND_EXECUTION]: The
scripts/verify.shutility performs static analysis on local project files to identify potential performance issues or resource leaks (e.g., module-scope connection pooling). The script uses standard system tools likefindandgrepin a read-only capacity and lacks network or persistence capabilities. - [INDIRECT_PROMPT_INJECTION]: The skill includes an attack surface through its ability to ingest and analyze user-controlled source code files.
- Ingestion points: Source code and environment files (
.js,.ts,.env) processed byscripts/verify.sh. - Boundary markers: Not applicable; the script uses grep-based pattern matching rather than complex parsing.
- Capability inventory: Limited to local filesystem reads and console output within the shell environment.
- Sanitization: The script performs literal matches and does not execute or evaluate the content of the scanned files, mitigating common injection vectors.
Audit Metadata