moai-baas-neon-ext

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is consistent with its stated purpose: Neon/PostgreSQL architecture, branching, performance, and migration guidance integrated with Context7 docs. I found no signs of deliberate malicious code, obfuscated payloads, or credential-harvesting endpoints. The main security concerns are: the Next.js example disables TLS verification (ssl.rejectUnauthorized = false), which should be corrected; logging slow query text could expose sensitive data in logs and should be redacted; and the allowed-tools scope is broad — ensure runtime authorization and least privilege for any agent executing these actions. Overall the skill is legitimate but requires standard operational safeguards before use (fix TLS config, limit logging of sensitive queries, and restrict agent/tool permissions).

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:08 AM
Package URL
pkg:socket/skills-sh/ajbcoding%2Fclaude-skill-eval%2Fmoai-baas-neon-ext%2F@ffd58f285172dcffb729ebdd1313198411239189