mongodb-population

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Analysis of the skill instructions and reference code shows no malicious intent or security vulnerabilities. The functionality is standard for database-related code generation.\n- [EXTERNAL_DOWNLOADS]: The skill recommends installing '@efesto-cloud/population' and '@efesto-cloud/mongodb-population'. These packages are recognized as vendor resources from the skill author and are required for the implementation.\n- [PROMPT_INJECTION]: The skill ingests user input for entity and field names, creating an indirect prompt injection surface.\n
  • Ingestion points: User input provided during the clarifying phase in SKILL.md.\n
  • Boundary markers: The skill does not specify explicit delimiters or boundary markers for the user-provided data.\n
  • Capability inventory: The skill performs file system reads (discovery) and writes (patching and creation) within the project structure.\n
  • Sanitization: No explicit validation or sanitization of user-provided names is mentioned in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 08:38 AM
Security Audit — agent-trust-hub — mongodb-population