mongodb
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill promotes security best practices, including using environment variables for credentials and implementing granular Role-Based Access Control (RBAC).
- [SAFE]: All external references and content sources originate from official MongoDB documentation or trusted GitHub repositories (e.g., Azure, MongoDB, GitHub), and are documented neutrally.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze user-provided artifacts such as database logs and application code. While this represents a surface for indirect prompt injection, it is central to its functionality as a diagnostic tool and is managed by instructions requiring verification of data against server status.
- [COMMAND_EXECUTION]: Administrative commands mentioned (e.g., rs.stepDown(), db.currentOp()) are standard for the intended DBA persona and do not indicate malicious intent.
Audit Metadata