{"data":{"skill":{"slug":"neondatabase-neon-postgres","name":"neon-postgres","icon":"📦","repo":"https://github.com/neondatabase/agent-skills/tree/main/skills/neon-postgres/","status":"approved","author":"neondatabase","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"885e65b6-04aa-4ed0-bb08-72a6088c2cea","skill_id":"d0af2ff2-de74-46d5-ad25-65e8445de86b","version":3,"content_hash":"v2:e397ce5a135369cd6def89cb6400d013e2f68f2f:c8555c5128d6c5b8e8a169535b5b1e91a77099c33300ae98de07c816664f4865:a838bf62116f8f08870b3d163a00c0c435ef6aa71926d9e7e584f221d46770b8:c5a91465ace43802ad4c52ca4d485ad6","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"The static external-command hits are markdown formatting, fixed documentation examples, or package names rather than executable skill code. The hardcoded URLs point to official Neon documentation, and the system-reconnaissance hit is a pooler hostname note. No prompt injection, credential exfiltration, or malicious intent was found in SKILL.md.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":29,"line_start":27},{"file":"SKILL.md","line_end":53,"line_start":29},{"file":"SKILL.md","line_end":65,"line_start":53},{"file":"SKILL.md","line_end":71,"line_start":65},{"file":"SKILL.md","line_end":87,"line_start":71},{"file":"SKILL.md","line_end":93,"line_start":87},{"file":"SKILL.md","line_end":166,"line_start":93}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":55,"line_start":55},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":89,"line_start":89},{"file":"SKILL.md","line_end":95,"line_start":95},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":103,"line_start":103},{"file":"SKILL.md","line_end":115,"line_start":115},{"file":"SKILL.md","line_end":121,"line_start":121},{"file":"SKILL.md","line_end":133,"line_start":133},{"file":"SKILL.md","line_end":145,"line_start":145},{"file":"SKILL.md","line_end":157,"line_start":157},{"file":"SKILL.md","line_end":169,"line_start":169},{"file":"SKILL.md","line_end":175,"line_start":175},{"file":"SKILL.md","line_end":186,"line_start":186}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":187,"audit_model":"codex","audited_at":"2026-07-06T19:47:16.752+00:00","created_at":"2026-07-06T21:37:11.120334+00:00","static_findings":[{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Append `.md` to the URL** (simplest): https://neon.com/docs/introduction/branching.md","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Request `text/markdown`** on the standard URL: `curl -H \"Accept: text/markdown\" https://neon.co","category":"external_commands","line_end":19,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":29,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":53,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use this for `@neondatabase/serverless` patterns, including HTTP queries, WebSocket transactions, an","category":"external_commands","line_end":65,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use this for local development enablement with `npx neonctl@latest init`, VSCode extension setup, an","category":"external_commands","line_end":71,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use this for terminal-first workflows, scripts, and CI/CD automation with `neonctl`.","category":"external_commands","line_end":87,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use this when implementing typed programmatic control of Neon resources in TypeScript via `@neondata","category":"external_commands","line_end":93,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use this when implementing programmatic Neon management in Python with the `neon-api` package.","category":"external_commands","line_end":166,"severity":"medium","line_start":93},{"id":"network:SKILL.md:18:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"1. **Append `.md` to the URL** (simplest): https://neon.com/docs/introduction/branching.md","category":"network","line_end":18,"severity":"low","line_start":18},{"id":"network:SKILL.md:19:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"2. **Request `text/markdown`** on the standard URL: `curl -H \"Accept: text/markdown\" https://neon.co","category":"network","line_end":19,"severity":"low","line_start":19},{"id":"network:SKILL.md:28:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"https://neon.com/docs/llms.txt","category":"network","line_end":28,"severity":"low","line_start":28},{"id":"network:SKILL.md:31:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Common doc URLs are organized in the topic links below. If you need a page not listed here, search t","category":"network","line_end":31,"severity":"low","line_start":31},{"id":"network:SKILL.md:37:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/ai/skills/neon-postgres/references/what-is-neon.md","category":"network","line_end":37,"severity":"low","line_start":37},{"id":"network:SKILL.md:43:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/ai/skills/neon-postgres/references/getting-started.md","category":"network","line_end":43,"severity":"low","line_start":43},{"id":"network:SKILL.md:49:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/ai/skills/neon-postgres/references/connection-methods.md","category":"network","line_end":49,"severity":"low","line_start":49},{"id":"network:SKILL.md:55:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/ai/skills/neon-postgres/references/neon-serverless.md","category":"network","line_end":55,"severity":"low","line_start":55},{"id":"network:SKILL.md:61:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/ai/skills/neon-postgres/references/neon-js.md","category":"network","line_end":61,"severity":"low","line_start":61},{"id":"network:SKILL.md:67:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/ai/skills/neon-postgres/references/devtools.md","category":"network","line_end":67,"severity":"low","line_start":67},{"id":"network:SKILL.md:73:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/ai/skills/neon-postgres/references/neon-cli.md","category":"network","line_end":73,"severity":"low","line_start":73},{"id":"network:SKILL.md:83:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/ai/skills/neon-postgres/references/neon-rest-api.md","category":"network","line_end":83,"severity":"low","line_start":83},{"id":"network:SKILL.md:89:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/ai/skills/neon-postgres/references/neon-typescript-sdk.md","category":"network","line_end":89,"severity":"low","line_start":89},{"id":"network:SKILL.md:95:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/ai/skills/neon-postgres/references/neon-python-sdk.md","category":"network","line_end":95,"severity":"low","line_start":95},{"id":"network:SKILL.md:101:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/ai/skills/neon-postgres/references/neon-auth.md","category":"network","line_end":101,"severity":"low","line_start":101},{"id":"network:SKILL.md:103:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Neon Auth is also embedded in the Neon JS SDK - so depending on your use case, you may want to use t","category":"network","line_end":103,"severity":"low","line_start":103},{"id":"network:SKILL.md:115:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/ai/skills/neon-postgres/references/branching.md","category":"network","line_end":115,"severity":"low","line_start":115},{"id":"network:SKILL.md:121:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/introduction/autoscaling.md","category":"network","line_end":121,"severity":"low","line_start":121},{"id":"network:SKILL.md:133:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/introduction/scale-to-zero.md","category":"network","line_end":133,"severity":"low","line_start":133},{"id":"network:SKILL.md:145:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/introduction/branch-restore.md","category":"network","line_end":145,"severity":"low","line_start":145},{"id":"network:SKILL.md:157:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/introduction/read-replicas.md","category":"network","line_end":157,"severity":"low","line_start":157},{"id":"network:SKILL.md:169:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/connect/connection-pooling.md","category":"network","line_end":169,"severity":"low","line_start":169},{"id":"network:SKILL.md:175:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/introduction/ip-allow.md","category":"network","line_end":175,"severity":"low","line_start":175},{"id":"network:SKILL.md:186:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Link: https://neon.com/docs/guides/logical-replication-guide.md","category":"network","line_end":186,"severity":"low","line_start":186},{"id":"blocker:SKILL.md:166:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Add `-pooler` to endpoint hostnames to use pooled connections.","category":"blocker","line_end":166,"severity":"low","line_start":166}],"finding_verdicts":[{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"This line describes appending .md to an official Neon documentation URL. Markdown formatting is not Ruby or shell execution, and no command is run.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"The inline curl example fetches a fixed official Neon documentation page as markdown. It has no interpolation, secret handling, or arbitrary command execution path.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"This finding points at a markdown code fence before a documentation index URL. It is formatting only, not executable Ruby or shell syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"This finding points at a markdown code fence after a documentation index URL. It is formatting only, not executable Ruby or shell syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"The backticks wrap the package name @neondatabase/serverless in prose. The line does not invoke a shell command or execute code.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The line mentions a fixed Neon CLI initialization command as documentation context. It is not embedded executable code and contains no user-controlled arguments.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The backticks wrap the neonctl tool name in prose about terminal workflows. This is documentation text, not command execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"The backticks wrap the package name @neondatabase/api-client. The line describes SDK usage and does not run a shell command.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"The backticks wrap the package name neon-api in prose. The line does not execute code or construct a command.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:18:hardcoded-url","reason":"The URL points to an official Neon documentation page and is used as a reference. There is no evidence of data exfiltration or a suspicious endpoint.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:19:hardcoded-url","reason":"The URL is a fixed official Neon documentation page used for markdown retrieval. The command does not send local data or credentials.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:28:hardcoded-url","reason":"The URL points to the official Neon documentation index for LLM use. It is a benign reference for locating docs.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:31:hardcoded-url","reason":"The URL points to the official Neon documentation index and is used to avoid guessing docs pages. No malicious network behavior is indicated.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:37:hardcoded-url","reason":"The URL points to an official Neon reference page about Neon concepts. It is documentation-only and not an exfiltration endpoint.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:43:hardcoded-url","reason":"The URL points to an official Neon getting-started reference. It is a legitimate documentation link.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:49:hardcoded-url","reason":"The URL points to official Neon connection-method documentation. It is a benign reference link.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:55:hardcoded-url","reason":"The URL points to official Neon serverless driver documentation. It does not indicate unsafe network use.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:61:hardcoded-url","reason":"The URL points to official Neon JS documentation. It is relevant to the skill purpose and not suspicious.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:67:hardcoded-url","reason":"The URL points to official Neon developer tools documentation. It is a normal reference for this skill.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:73:hardcoded-url","reason":"The URL points to official Neon CLI documentation. It is expected for a Neon guidance skill.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:83:hardcoded-url","reason":"The URL points to official Neon REST API documentation. It is a benign reference for API guidance.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:89:hardcoded-url","reason":"The URL points to official Neon TypeScript SDK documentation. It is relevant and not an exfiltration endpoint.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:95:hardcoded-url","reason":"The URL points to official Neon Python SDK documentation. It is documentation-only and not suspicious.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:101:hardcoded-url","reason":"The URL points to official Neon Auth documentation. It is a legitimate reference for authentication guidance.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:103:hardcoded-url","reason":"The URL points to official Neon connection-method documentation from explanatory prose. It does not request or transmit user data.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:115:hardcoded-url","reason":"The URL points to official Neon branching documentation. It is expected reference material for this skill.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:121:hardcoded-url","reason":"The URL points to official Neon autoscaling documentation. It is a benign documentation link.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:133:hardcoded-url","reason":"The URL points to official Neon scale-to-zero documentation. It is relevant reference material.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:145:hardcoded-url","reason":"The URL points to official Neon restore documentation. It is a legitimate operational reference.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:157:hardcoded-url","reason":"The URL points to official Neon read-replica documentation. It is expected for database operations guidance.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:169:hardcoded-url","reason":"The URL points to official Neon connection-pooling documentation. It is not a suspicious destination.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:175:hardcoded-url","reason":"The URL points to official Neon IP allow-list documentation. It is legitimate security configuration guidance.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:186:hardcoded-url","reason":"The URL points to official Neon logical replication documentation. It is a benign reference link.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:166:system-reconnaissance","reason":"The line says to add -pooler to Neon endpoint hostnames for pooled connections. This is product configuration guidance, not system reconnaissance.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}