neon-postgres-branches

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts exclusively with official Neon resources, including the neon CLI tool, the @neon/config NPM package, and documentation hosted on neon.com. These are verified resources provided by the vendor, neondatabase.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a data ingestion surface where user-supplied branch names or project IDs are used in shell commands and file-writing operations (updating .env files).
  • Ingestion points: User-provided inputs for placeholders like <branch-name> and <project-id> in SKILL.md.
  • Boundary markers: The instructions include a clear directive to the agent: "Never overwrite an existing env key without explicit confirmation."
  • Capability inventory: The skill uses the neon CLI for branch management and has the ability to write connection strings to local environment files.
  • Sanitization: Security is maintained through a mandatory human-in-the-loop confirmation step before any file system modifications occur.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 01:46 AM
Security Audit — agent-trust-hub — neon-postgres-branches