Back to plugin

Security audit

Postgres AIops

Security checks for vulnerabilities and agentic risk

Overview

This plugin clearly describes a PostgreSQL operations tool with disclosed database read/write powers, credential handling, audit logging, and no hidden or unrelated behavior in the inspected artifacts.

Install this only for PostgreSQL environments where you want an agent to inspect and potentially change database state. Start with a read-only or least-privilege PostgreSQL role, review dry-run output before maintenance actions, and treat irreversible operations such as terminate/cancel, VACUUM FULL, REINDEX, and query-stat resets as production-impacting even though they are audited.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
skills/postgres-aiops/references/agent-guardrails.md:31
Evidence
Copy this into your agent's system prompt: