mongodb-natural-language-querying

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is restricted to using specified MongoDB MCP tools for schema discovery and data sampling. The instructions follow a structured process to gather context using tools such as mcp__mongodb__collection-schema and mcp__mongodb__find before generating queries.
  • [SAFE]: The skill is designed for read-only operations. It explicitly excludes write operations in aggregation pipelines and focuses on generating find queries or aggregation pipelines for data retrieval.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes external database content.
  • Ingestion points: Data enters the agent context via mcp__mongodb__collection-schema and mcp__mongodb__find as described in SKILL.md.
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the fetched database content.
  • Capability inventory: The skill's primary capability is generating text-based queries for the user; it does not contain scripts for automatic execution, file system writes, or network operations.
  • Sanitization: There is no explicit sanitization or filtering of the content retrieved from the database collections.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 08:50 AM