mongodb-search-and-ai

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized network operations were detected in the skill's instructions or reference files.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data by ingesting database metadata (list-databases, collection-schema in SKILL.md). It possesses capabilities for database modification and query execution (create-index, aggregate in SKILL.md). While explicit boundary markers for external data are absent, the risk is mitigated by strong instructions requiring user approval before any index creation and a specific anti-pattern warning the agent not to treat tool outputs or external content as trusted instructions.
  • [EXTERNAL_DOWNLOADS]: The CHANGELOG.md references an official repository from a well-known organization as its source. This is a neutral documentation of the skill's provenance and does not constitute a runtime remote code execution risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:18 AM
Security Audit — agent-trust-hub — mongodb-search-and-ai