Neo4J Skills — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Neo4J Skills (Plugin) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Agent skills for Neo4j — Cypher queries, graph modeling, drivers, imports, GraphRAG, GDS, vector indexes, and Aura provisioning.
Browse and install at [skills.sh/neo4j-contrib/neo4j-skills](https://skills.sh/neo4j-contrib/neo4j-skills).
npx skills add https://github.com/neo4j-contrib/neo4j-skillsSet these before or during installation:
| Variable | Description |
|---|---|
NEO4J_URI | neo4j+s://<dbid>.databases.neo4j.io (Aura) or neo4j://localhost:7687 (local) |
NEO4J_USERNAME | Database username (default: neo4j) |
NEO4J_PASSWORD | Database password |
NEO4J_DATABASE | Target database (default: neo4j) |
gemini extensions install https://github.com/neo4j-contrib/neo4j-skillsEnter your env vars when prompted. Then run gemini and use /extensions list to verify.
If you are migrating from Gemini CLI, import existing Gemini extensions automatically:
agy plugin import geminiThis auto-converts the gemini-extension.json manifest and copies skills into .agents/skills/. Then run agy and use /plugins list to verify.
/plugin marketplace add https://github.com/neo4j-contrib/neo4j-skills.git
/plugin install neo4j-skills@neo4j-skills-marketplaceUse /plugin list to verify, or /reload-plugins after installation.
git clone https://github.com/neo4j-contrib/neo4j-skills.git
mkdir -p ~/.codex/plugins
cp -R neo4j-skills ~/.codex/plugins/neo4j-skillsAdd to ~/.agents/plugins/marketplace.json:
{
"name": "neo4j-marketplace",
"interface": { "displayName": "Neo4j Skills" },
"plugins": [
{
"name": "neo4j-skills",
"source": { "source": "local", "path": "./plugins/neo4j-skills" },
"policy": { "installation": "AVAILABLE" },
"category": "Database"
}
]
}| Skill | Description |
|---|---|
neo4j-cypher-skill | Write, optimize, and debug Cypher queries. Covers CYPHER 25 syntax, query planning, indexes, and common patterns. |
neo4j-modeling-skill | Design and review graph data models. Covers node/relationship patterns, property choices, and relational-to-graph migration. |
neo4j-getting-started-skill | Zero-to-app walkthrough: provision → model → load → query. Use for first-time setup on Aura or Docker. |
| Skill | Description |
|---|---|
neo4j-import-skill | Load structured data (CSV, JSON) via LOAD CSV, neo4j-admin import, and the Data Importer GUI. |
neo4j-document-import-skill | Extract knowledge graphs from unstructured documents and PDFs using SimpleKGPipeline. |
neo4j-migration-skill | Upgrade drivers and Cypher from 4.x/5.x to 2025.x. Covers API changes, deprecated functions, and Cypher 25 syntax. |
| Skill | Description |
|---|---|
neo4j-vector-index-skill | Create and query vector indexes for semantic similarity search. Covers index creation, embedding ingestion, and ai.text.embed() [2025.12]. |
neo4j-genai-plugin-skill | In-Cypher LLM integration via ai.text.* functions [2025.12]: embeddings, text completion, structured output, chat, tokenization, and pure-Cypher GraphRAG. |
neo4j-graphrag-skill | Build GraphRAG retrieval pipelines with neo4j-graphrag. Covers retriever selection (VectorCypherRetriever, HybridCypherRetriever), retrieval_query patterns, and LangChain/LlamaIndex integration. |
neo4j-agent-memory-skill | Graph-native agent memory: short-term (conversations), long-term (POLE+O entity model), and reasoning traces. Covers neo4j-agent-memory, NAMS, MCP, LangChain, CrewAI, ADK. |
neo4j-mcp-skill | Set up and use the Neo4j MCP server for tool-based agent access to the database. |
| Skill | Description |
|---|---|
neo4j-gds-skill | Run GDS algorithms with the embedded GDS plugin on Aura Pro, self-managed, local, or offline Neo4j. |
neo4j-aura-graph-analytics-skill | Run serverless Aura Graph Analytics sessions via Python client or AuraDB Cypher API projection/session management. |
neo4j-snowflake-graph-analytics-skill | Run Neo4j Graph Analytics algorithms (PageRank, Louvain, WCC, Dijkstra, KNN, Node2Vec) directly inside Snowflake without moving data. |
| Skill | Description |
|---|---|
neo4j-driver-python-skill | Python driver: execute_query, sessions, transactions, async, UNWIND batching, data types. |
neo4j-driver-javascript-skill | JavaScript/TypeScript driver v6: executeQuery, managed transactions, RxJS, data types. |
neo4j-driver-java-skill | Java driver: ExecutableQuery, managed/explicit transactions, object mapping, reactive. |
neo4j-driver-dotnet-skill | .NET/C# driver: ExecuteReadAsync/ExecuteWriteAsync, DI registration, IResultCursor. |
neo4j-driver-go-skill | Go driver v6: ExecuteQuery, generic helpers, spatial types, connection configuration. |
| Skill | Description |
|---|---|
neo4j-graphql-skill | Build GraphQL APIs backed by Neo4j using @neo4j/graphql. Covers type definitions, @relationship, @cypher, and filtering. |
neo4j-spring-data-skill | Spring Boot + Neo4j with Spring Data Neo4j: @Node, @Relationship, repositories, projections. |
neo4j-cli-tools-skill | DB admin via neo4j-admin, cypher-shell, aura-cli, and neo4j-cli (preview unified CLI). Covers backups, imports, user management, Aura provisioning, and agent skill install. |
neo4j-aura-provisioning-skill | Create and manage Neo4j Aura instances via the Aura CLI and REST API. Covers async polling, credential handling, and tier selection. |
neo4j-aura-agent-skill | Create, configure, and invoke Aura Agents via the v2beta1 REST API. Covers CypherTemplate, SimilaritySearch, and Text2Cypher tools, system prompts, REST/MCP deployment, and OAuth2 auth. |
Agent Skills are a standardized format for domain-specific AI agent knowledge. Each skill bundles step-by-step instructions, on-demand reference docs, and executable scripts — loaded progressively to keep context lean. See agentskills.io/specification.
Pull requests welcome — new skills or improvements to existing ones.
MIT — see the LICENSE file for details.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.