mongodb-docs
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is designed to ground agent responses in official MongoDB documentation. All external links point to
mongodb.com, which is a well-known and trusted service. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch and process content from external web pages (official MongoDB documentation). Ingesting external data is a standard functional requirement for this skill but technically represents an attack surface where instructions embedded in external content could influence agent behavior.
- Ingestion points: Official documentation pages at
mongodb.com/docsand markdown variants. - Boundary markers: The skill instructs the agent to use specific framing such as "According to MongoDB docs..." and "Inference: ...", which helps distinguish documentation content from agent logic.
- Capability inventory: The skill does not possess capabilities for file-writing, network exfiltration, or command execution.
- Sanitization: No specific sanitization or filtering of documentation content is defined.
Audit Metadata