api-database-mongoose

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: In examples/core.md, a hardcoded MongoDB connection string (mongodb://admin:password123@localhost:27017/mydb) is included within a 'Bad Example' section designed to teach users not to hardcode credentials. While the surrounding text correctly advises using environment variables, the string itself contains embedded credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and processing of data within a database environment, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: Data enters the agent's database context through operations such as User.create, save(), and findByIdAndUpdate() as shown in examples/core.md and examples/transactions.md.
  • Boundary markers: The implementation patterns do not include specific boundary delimiters or instructions to ignore embedded commands within the ingested data fields.
  • Capability inventory: The skill provides comprehensive CRUD (Create, Read, Update, Delete) capabilities and network connectivity to MongoDB databases.
  • Sanitization: Security relies on Mongoose schema-level validation, including enum, match, and required constraints, as well as automatic type casting.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:07 PM
Security Audit — agent-trust-hub — api-database-mongoose