This PostgreSQL assistant is not clearly malicious, but it has powerful database, synchronization, and external-LLM access with weak scoping and unsafe secret-handling practices.
Review carefully before installing. Use only with dedicated least-privileged database accounts, avoid production data until tested, take backups before enabling sync or partition operations, and assume updates and deletes can propagate to targets. Do not pass passwords or API keys on the command line; prefer environment variables or a real secret manager. Configure external LLM endpoints only if SQL text and schema details are allowed to leave your environment.