agent-mongo
Warn
Audited by Socket on Jul 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK rather than confirmed malware. The skill’s MongoDB behaviors are purpose-aligned, but its trust model is weak: it depends on an unverifiable local `agent-mongo` binary and forwards database credentials to it, which by policy requires elevated risk scoring.
Confidence: 86%Severity: 84%
Audit Metadata