Back to skill

Security audit

Pg Mcp Skills Free

Security checks across malware telemetry and agentic risk

Overview

This is a coherent PostgreSQL administration helper, with database-write risk disclosed and confirmation/read-only safeguards described.

Install this only where the configured PostgreSQL MCP server has permissions appropriate for the databases you want the agent to manage. Use read-only MCP credentials for production, review every generated SQL statement carefully, and do not approve UPDATE, DELETE, DROP, INSERT, or ALTER actions unless you intend the database change.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger condition is so broad that the skill may activate for many ordinary requests involving databases, SQL, or storage, even when the user did not intend operational actions. In a skill with exec and write capabilities, over-triggering increases the chance of inappropriate tool routing, unnecessary environment probing, or accidental progression toward sensitive database operations.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The intent examples use vague phrases like '慢' or general performance language that can overlap with casual discussion, causing the skill to misclassify requests and enter sensitive database workflows. Because this skill advertises MCP-backed database operations and includes write/exec tooling, imprecise routing can expand the attack surface and raise the risk of unintended actions or disclosure of database metadata.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.