Back to skill

Security audit

neon-ai-gateway

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Neon AI Gateway guide, but users should knowingly approve Neon credential, deployment, and parent-skill install steps.

Install this when you intend to use Neon AI Gateway. Review before allowing it to install the parent neon skill, run Neon deploy/config commands, or write NEON_AI_GATEWAY_TOKEN values into local env files; those actions are expected for the integration but affect your project and credentials.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad phrases like 'call an LLM', 'add AI to my app', and 'chat completion', which are common requests that may match many unrelated contexts. This can cause the skill to be invoked when it is not the best fit, increasing the chance that users are steered into Neon-specific setup, credential handling, or external fetch/install steps without clear intent.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
81% confidence
Finding

The skill instructs the agent to fetch or install a parent skill from an external URL/CLI command if it is not already present. This expands trust to additional remote content at runtime and can enable skill enumeration or supply-chain style exposure, especially if the fetched parent skill changes over time or contains conflicting instructions.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

FIRST: Use the parent neon skill for a Neon overview, getting started with Neon, Neon development best practices, and more.

If the neon skill is not installed, fetch it from https://neon.com/docs/ai/skills/neon/SKILL.md or install it with:

bash
neon skills -s neon -y

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

md
When `aiGateway` is enabled, Neon injects the gateway credentials as **Neon-branded** env vars. Inside a deployed Neon Function these are injected automatically; locally, `neon env pull` writes them to `.env`/`.env.local` (or use `neon-env run -- <cmd>` to inject at runtime without a file):

| Variable                   | Meaning                                                                                                                             |
| -------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `NEON_AI_GATEWAY_TOKEN`    | Gateway bearer token (a Neon credential, `nt_live_...`)                                                                              |
| `NEON_AI_GATEWAY_BASE_URL` | **Bare branch gateway host** (`scheme://host`, **no path** — no `/ai-gateway`): `https://<branch-id>-api.ai.<region>.aws.neon.tech` |

Static analysis

No suspicious patterns detected.