mongodb
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns or behaviors were identified in the skill instructions or supporting files.
- [COMMAND_EXECUTION]: The skill includes a bash utility script,
scripts/verify.sh, designed for local project linting. The script uses standard Unix tools (find,grep,sed) to perform read-only static analysis on user-provided JavaScript files. It also usesnode --checkfor syntax validation, which verifies code structure without execution. - [CREDENTIALS_UNSAFE]: The skill implements proactive security measures by including automated checks in
scripts/verify.shto identify and warn against hardcoded MongoDB connection strings in application code. It encourages the use of environment variables for secret management. - [INDIRECT_PROMPT_INJECTION]: The skill includes a verification script that processes untrusted project data. 1. Ingestion points: The
scripts/verify.shscript reads contents of.jsand.mongodb.jsfiles from the project root. 2. Boundary markers: The script does not use specific markers to delimit data but relies on file discovery. 3. Capability inventory: The script performs file system discovery, text pattern matching, and syntax validation. 4. Sanitization: The script performs static analysis and does not execute the ingested content or pass it directly into the agent's prompt in an unsafe manner.
Audit Metadata