I have no clue how you’re running your agents or what you’re building, but giving the raw password string to a the model seems dubious?
Otherwise, why not just keep the password in an .env file, and state “grab the password from the .env file” in your Postgres skill?