agent-mongo

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated MongoDB read-only purpose is coherent, and its data flow to MongoDB is proportionate, but trust breaks on the undeclared provenance of the required agent-mongo binary. Because the skill requires an unverifiable executable and forwards MongoDB credentials to it, this is a high security-risk skill even without direct evidence of malicious exfiltration.

Confidence: 84%Severity: 86%
Audit Metadata
Analyzed At
Sep 3, 2026, 10:01 AM
Package URL
pkg:socket/skills-sh/shhac%2Fagent-skills%2Fagent-mongo%2F@d7a06266127aa86dde6755de7bba9ba93245998fd9a24634fbceda4cb1c3b3dd
Security Audit — socket — agent-mongo