agent-mongo

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK rather than confirmed malware. The skill’s MongoDB behaviors are purpose-aligned, but its trust model is weak: it depends on an unverifiable local `agent-mongo` binary and forwards database credentials to it, which by policy requires elevated risk scoring.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Jul 7, 2026, 01:37 PM
Package URL
pkg:socket/skills-sh/shhac%2Fagent-skills%2Fagent-mongo%2F@9f2049e8200733405092be0d9a4e1500854d92015de297036191d2a0cde24907
Security Audit — socket — agent-mongo