api-database-mongoose
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill follows security best practices by recommending the use of environment variables for database connection strings and explicitly documenting hardcoded credentials as an anti-pattern to avoid.
- [SAFE]: The technical recommendation to use
127.0.0.1instead oflocalhostis a legitimate mitigation for Node.js 18+ IPv6 connection timeout issues and does not constitute a malicious redirection or obfuscation. - [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for ingesting external data into database operations, which creates a potential surface for indirect prompt injection if the ingested data contains malicious instructions. However, the skill provides extensive documentation on mitigating this via schema-level validation (e.g.,
runValidators: true,min/maxconstraints, and regex matching). - Ingestion points: Database connection URI from
process.env.MONGODB_URIincore.md, and application data inputs (e.g.,orderData) intransactions.md. - Boundary markers: The skill relies on Mongoose schema definitions as the primary boundary for data integrity.
- Capability inventory: Full database CRUD operations (create, read, update, delete) and connection management.
- Sanitization: Explicitly mandates the use of schema validators (required, enum, minlength, maxlength, match) and encourages the
runValidators: trueoption for direct updates to ensure data conforms to expected formats.
Audit Metadata