neon-object-storage

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capability is aligned with a Neon Object Storage skill and most data flows target official Neon services, but the skill expands trust by telling the agent to fetch/install a parent skill and by recommending a third-party Files SDK from an unrelated publisher that will receive storage credentials. This is not fundamentally incompatible with the stated purpose, so it is not malicious, but the transitive skill installation, docs inconsistency, and credential-forwarding to third-party code make the overall footprint medium risk.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Sep 17, 2026, 08:11 PM
Package URL
pkg:socket/skills-sh/neondatabase%2Fagent-skills%2Fneon-object-storage%2F@ba00b37df94de4fb97bc773ce0c085e90d7d35a41994f413cdf69a84a0201a9b
Security Audit — socket — neon-object-storage