The skill lacks defined tool constraints and network permissions while accessing sensitive environment variables, creating an unmonitored attack surface that risks unauthorized data exfiltration and system compromise.
npx skills add https://github.com/neondatabase/agent-skillsAccess to sensitive environment variables detected
$DATABASE_URL
Skill does not specify a license field. Specifying a license helps users understand usage terms.
Skill description is empty or too short. A clear description helps users evaluate the skill's purpose.
[](https://mondoo.com/ai-agent-security/skills/github/neondatabase/agent-skills/claimable-postgres)<a href="https://mondoo.com/ai-agent-security/skills/github/neondatabase/agent-skills/claimable-postgres"><img src="https://mondoo.com/ai-agent-security/api/badge/github/neondatabase/agent-skills/claimable-postgres.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/neondatabase/agent-skills/claimable-postgres.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.