neon-object-storage
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core capability is aligned with a Neon Object Storage skill and most data flows target official Neon services, but the skill expands trust by telling the agent to fetch/install a parent skill and by recommending a third-party Files SDK from an unrelated publisher that will receive storage credentials. This is not fundamentally incompatible with the stated purpose, so it is not malicious, but the transitive skill installation, docs inconsistency, and credential-forwarding to third-party code make the overall footprint medium risk.
Confidence: 90%Severity: 58%
Audit Metadata