claimable-postgres

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (provision quick, no-signup temporary Postgres databases and write connection details to an env file) is coherent with the described HTTP-based provisioning flow, multiple delivery methods, and the resulting data artifacts (connection_string, claim_url, expires_at). There is a reasonable, proportionate data flow to an external API and local env file writes. The footprint stays within expected boundaries for a developer tooling helper. No unverifiable binaries or credential forwarding patterns are evident. The main risks are typical for remote provisioning tools: potential accidental exposure of database URLs in shared repos or logs and the reliance on the external service for ephemeral resources. Overall verdict: BENIGN with cautions (suspicious-level risk notes kept moderate due to data exposure potential).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 08:12 PM
Package URL
pkg:socket/skills-sh/neondatabase%2Fagent-skills%2Fclaimable-postgres%2F@b13af5ef7a10f5a3ecc6f9c6060481f3fdf50a59