mongodb-schema-design
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of educational documentation and architectural guidance for MongoDB schema design. It contains no executable scripts or command-line tools.
- [SAFE]: All external references and documentation links target official MongoDB domains or well-known development repositories.
- [SAFE]: The skill documents integration with the MongoDB MCP server and explicitly establishes an 'Action Policy' requiring manual user confirmation for any write or destructive database operations (such as updates, deletions, or collection drops).
- [PROMPT_INJECTION]: The skill provides instructions for the agent to ingest and analyze user-controlled database content using MCP tools like 'mcp__mongodb__collection-schema' and 'mcp__mongodb__aggregate'. While this creates an indirect prompt injection surface if a database contains adversarial data, the documented safety policy of requiring human approval for subsequent actions serves as a primary mitigation against automated exploitation.
Audit Metadata