diff --git a/skills/neon-ai-gateway/spec.yaml b/skills/neon-ai-gateway/spec.yaml index a55db685..a53272eb 100644 --- a/skills/neon-ai-gateway/spec.yaml +++ b/skills/neon-ai-gateway/spec.yaml @@ -19,9 +19,9 @@ metadata: spec: repository: "https://github.com/neondatabase/agent-skills" - ref: "b5beae8767c18ee7b9dc1ae1eb6c93c7cb1a96c4" # main as of 2026-09-18 + ref: "e8be8ff34267b559c90106a5e0bafd3071e76d46" # main as of 2026-09-18 path: "skills/neon-ai-gateway" - version: "0.1.0" + version: "0.1.1" provenance: repository_uri: "https://github.com/neondatabase/agent-skills" diff --git a/skills/neon-auth/spec.yaml b/skills/neon-auth/spec.yaml index edc0de9b..0fb826db 100644 --- a/skills/neon-auth/spec.yaml +++ b/skills/neon-auth/spec.yaml @@ -17,9 +17,9 @@ metadata: spec: repository: "https://github.com/neondatabase/agent-skills" - ref: "b5beae8767c18ee7b9dc1ae1eb6c93c7cb1a96c4" # main as of 2026-09-18 + ref: "e8be8ff34267b559c90106a5e0bafd3071e76d46" # main as of 2026-09-18 path: "skills/neon-auth" - version: "0.1.0" + version: "0.1.1" provenance: repository_uri: "https://github.com/neondatabase/agent-skills" diff --git a/skills/neon-object-storage/spec.yaml b/skills/neon-object-storage/spec.yaml index 9c4e3bf9..8d9ad926 100644 --- a/skills/neon-object-storage/spec.yaml +++ b/skills/neon-object-storage/spec.yaml @@ -19,9 +19,9 @@ metadata: spec: repository: "https://github.com/neondatabase/agent-skills" - ref: "b5beae8767c18ee7b9dc1ae1eb6c93c7cb1a96c4" # main as of 2026-09-18 + ref: "e8be8ff34267b559c90106a5e0bafd3071e76d46" # main as of 2026-09-18 path: "skills/neon-object-storage" - version: "0.1.0" + version: "0.1.1" provenance: repository_uri: "https://github.com/neondatabase/agent-skills" diff --git a/skills/neon-postgres-branches/spec.yaml b/skills/neon-postgres-branches/spec.yaml index a03d051f..ccf14e57 100644 --- a/skills/neon-postgres-branches/spec.yaml +++ b/skills/neon-postgres-branches/spec.yaml @@ -16,9 +16,9 @@ metadata: spec: repository: "https://github.com/neondatabase/agent-skills" - ref: "b5beae8767c18ee7b9dc1ae1eb6c93c7cb1a96c4" # main as of 2026-09-18 + ref: "e8be8ff34267b559c90106a5e0bafd3071e76d46" # main as of 2026-09-18 path: "skills/neon-postgres-branches" - version: "0.1.0" + version: "0.1.1" provenance: repository_uri: "https://github.com/neondatabase/agent-skills" @@ -26,5 +26,7 @@ provenance: security: allowed_issues: + - rule_id: LLM_PROMPT_INJECTION + reason: "Accepted risk: when its bundled `neon` parent is absent, `SKILL.md:19-22` fetches that parent from the official Neon domain or installs it through Neon CLI. This is a documented same-publisher dependency path, not an untrusted third-party source; the mutable remote content is intentionally not pinned to this artifact." - rule_id: MANIFEST_MISSING_LICENSE reason: "neondatabase/agent-skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter." diff --git a/skills/neon-postgres-egress-optimizer/spec.yaml b/skills/neon-postgres-egress-optimizer/spec.yaml index 6296f89f..df9af226 100644 --- a/skills/neon-postgres-egress-optimizer/spec.yaml +++ b/skills/neon-postgres-egress-optimizer/spec.yaml @@ -9,9 +9,9 @@ metadata: spec: repository: "https://github.com/neondatabase/agent-skills" - ref: "b5beae8767c18ee7b9dc1ae1eb6c93c7cb1a96c4" # main as of 2026-09-18 + ref: "e8be8ff34267b559c90106a5e0bafd3071e76d46" # main as of 2026-09-18 path: "skills/neon-postgres-egress-optimizer" - version: "0.1.9" + version: "0.1.10" provenance: repository_uri: "https://github.com/neondatabase/agent-skills" diff --git a/skills/neon-postgres/spec.yaml b/skills/neon-postgres/spec.yaml index fd643384..12942981 100644 --- a/skills/neon-postgres/spec.yaml +++ b/skills/neon-postgres/spec.yaml @@ -9,9 +9,9 @@ metadata: spec: repository: "https://github.com/neondatabase/agent-skills" - ref: "b5beae8767c18ee7b9dc1ae1eb6c93c7cb1a96c4" # main as of 2026-09-18 + ref: "e8be8ff34267b559c90106a5e0bafd3071e76d46" # main as of 2026-09-18 path: "skills/neon-postgres" - version: "0.1.9" + version: "0.1.10" provenance: repository_uri: "https://github.com/neondatabase/agent-skills" diff --git a/skills/neon/spec.yaml b/skills/neon/spec.yaml index 4b79b166..d8317eb9 100644 --- a/skills/neon/spec.yaml +++ b/skills/neon/spec.yaml @@ -19,9 +19,9 @@ metadata: spec: repository: "https://github.com/neondatabase/agent-skills" - ref: "b5beae8767c18ee7b9dc1ae1eb6c93c7cb1a96c4" # main as of 2026-09-18 + ref: "e8be8ff34267b559c90106a5e0bafd3071e76d46" # main as of 2026-09-18 path: "skills/neon" - version: "0.1.0" + version: "0.1.1" provenance: repository_uri: "https://github.com/neondatabase/agent-skills" @@ -29,5 +29,7 @@ provenance: security: allowed_issues: + - rule_id: ATR_2026_00063 + reason: "FP: `references/claimable-neon.md:41` documents `neon claim create` writing its provisioned variables to `.env` or `.env.local`, with safeguards for existing Neon-managed keys and gitignore. It neither reads a host secret nor transmits data to an external sink, so it is not a multi-skill exfiltration chain." - rule_id: MANIFEST_MISSING_LICENSE reason: "neondatabase/agent-skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter."