agent-paste-neon-postgres

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of official tools such as neonctl and the Neon MCP server via npx. These downloads originate from well-known service providers associated with the platform.- [REMOTE_CODE_EXECUTION]: Instructions are provided to fetch and install modular skill extensions from the official repository using a package-like installation workflow.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the user's workspace, such as environment variables and configuration files, to customize the setup process. * Ingestion points: Project codebase inspection and .env file reading as described in SKILL.md. * Boundary markers: Absent. * Capability inventory: Shell command execution via npx and extension management through the IDE interface. * Sanitization: None identified in the provided instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 12:07 PM
Security Audit — agent-trust-hub — agent-paste-neon-postgres