api-database-mongoose

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill follows security best practices by recommending the use of environment variables for database connection strings and explicitly documenting hardcoded credentials as an anti-pattern to avoid.
  • [SAFE]: The technical recommendation to use 127.0.0.1 instead of localhost is a legitimate mitigation for Node.js 18+ IPv6 connection timeout issues and does not constitute a malicious redirection or obfuscation.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for ingesting external data into database operations, which creates a potential surface for indirect prompt injection if the ingested data contains malicious instructions. However, the skill provides extensive documentation on mitigating this via schema-level validation (e.g., runValidators: true, min/max constraints, and regex matching).
  • Ingestion points: Database connection URI from process.env.MONGODB_URI in core.md, and application data inputs (e.g., orderData) in transactions.md.
  • Boundary markers: The skill relies on Mongoose schema definitions as the primary boundary for data integrity.
  • Capability inventory: Full database CRUD operations (create, read, update, delete) and connection management.
  • Sanitization: Explicitly mandates the use of schema validators (required, enum, minlength, maxlength, match) and encourages the runValidators: true option for direct updates to ensure data conforms to expected formats.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:46 PM
Security Audit — agent-trust-hub — api-database-mongoose