mongodb-schema-design

Pass

Audited by Gen Agent Trust Hub on Mar 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: No security issues detected. The skill follows best practices for providing instructional content and utilizes trusted tools for database integration.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing and using the mongodb-mcp-server via npx. This package is a well-known utility for connecting agents to MongoDB instances and is maintained by the official MongoDB community organization. References to official MongoDB documentation are used throughout the rules to provide context. Per the trusted scope rule, these references are considered safe and do not escalate the verdict.
  • [COMMAND_EXECUTION]: The skill provides numerous MongoDB shell commands for users to execute to verify their schema designs. It also uses the MongoDB MCP server to execute read-only diagnostic commands such as aggregate and db-stats to inform its recommendations. The skill explicitly states that it will never perform write operations without user approval and recommends using the --readOnly flag for safety.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 9, 2026, 09:07 PM