mongodb
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data fetched from external MongoDB databases which may contain untrusted content. If an agent processes this data without sanitization, it could influence the agent's behavior.
- Ingestion points: Data is ingested via
mongosh --evalcommands (e.g.,db.collection.find()) inSKILL.md. - Boundary markers: None identified in the prompt templates.
- Capability inventory: The skill can execute shell commands via Docker, read/write to the host filesystem via volume mounts defined in
manifest.toml, and perform network operations to connect to database servers. - Sanitization: No explicit sanitization or escaping of database content is performed before returning it to the agent context.
- [COMMAND_EXECUTION]: The skill relies on executing commands within a Docker container using
mongosh --eval. This is the intended primary purpose of the skill to allow database interaction. - [DATA_EXPOSURE]: The
manifest.tomlfile configures volume mounts["${PWD}:/backup"]and["${PWD}:/export"]for themongodump,mongorestore, andmongoexportvariants. This exposes the host's current working directory to the container, which is necessary for the tool's backup and export functionality but requires the user to run the skill from a non-sensitive directory.
Audit Metadata