neon-postgres
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches current documentation and technical guides from Neon's official domain (
neon.com) to ensure the agent has up-to-date information. - [EXTERNAL_DOWNLOADS]: References official ecosystem packages for database interaction and management, including
@neondatabase/serverless,@neondatabase/neon-js,@neondatabase/auth,@neondatabase/api-client, and theneon-apiPython package. - [INDIRECT_PROMPT_INJECTION]: The skill processes external documentation content, which presents a surface for indirect prompt injection if the source content were compromised.
- Ingestion points: Documentation URLs located under
https://neon.com/docs/(as described inSKILL.md). - Boundary markers: The skill does not explicitly instruct the agent to use delimiters or ignore potential commands embedded within the fetched documentation content.
- Capability inventory: The skill facilitates the use of the Neon CLI (
neonctl) and various SDKs, which involves executing shell commands and performing network operations. - Sanitization: There is no evidence of content sanitization or validation for the documentation fetched at runtime.
Audit Metadata