agent-mongo
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated MongoDB read-only purpose is coherent, and its data flow to MongoDB is proportionate, but trust breaks on the undeclared provenance of the required agent-mongo binary. Because the skill requires an unverifiable executable and forwards MongoDB credentials to it, this is a high security-risk skill even without direct evidence of malicious exfiltration.
Confidence: 84%Severity: 86%
Audit Metadata