mongodb-natural-language-querying
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is restricted to using specified MongoDB MCP tools for schema discovery and data sampling. The instructions follow a structured process to gather context using tools such as mcp__mongodb__collection-schema and mcp__mongodb__find before generating queries.
- [SAFE]: The skill is designed for read-only operations. It explicitly excludes write operations in aggregation pipelines and focuses on generating find queries or aggregation pipelines for data retrieval.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes external database content.
- Ingestion points: Data enters the agent context via mcp__mongodb__collection-schema and mcp__mongodb__find as described in SKILL.md.
- Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the fetched database content.
- Capability inventory: The skill's primary capability is generating text-based queries for the user; it does not contain scripts for automatic execution, file system writes, or network operations.
- Sanitization: There is no explicit sanitization or filtering of the content retrieved from the database collections.
Audit Metadata