mongodb-natural-language-querying

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface by ingesting untrusted data from external sources.
  • Ingestion points: The skill uses mcp__mongodb__collection-schema and mcp__mongodb__find to read database structure and content into the agent context (SKILL.md).
  • Boundary markers: There are no specific instructions or delimiters to isolate the retrieved data from the agent's instructions.
  • Capability inventory: The skill is restricted to the mcp__mongodb__* toolset for database operations. It does not have access to general shell execution, network tools (curl/wget), or file system writes.
  • Sanitization: No sanitization or validation of the retrieved database content is performed before processing.
  • [SAFE]: The skill's operations are consistent with its stated purpose of providing natural language querying for MongoDB. All external tools utilized are within the mcp__mongodb namespace, belonging to the vendor.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:14 AM
Security Audit — agent-trust-hub — mongodb-natural-language-querying