hap-mongodb-slowlog-analysis

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This is a coherent MongoDB slow-log analysis helper with no executable code, hidden data transfer, persistence, or automatic database changes found.

Before installing, treat slow logs as potentially sensitive and redact business values if needed. Review any generated MongoDB index commands carefully, test with explain output or staging data, and consider production storage and write-performance impact before running them.

SkillSpector (2)

By NVIDIA

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The description states 'Prefer Chinese output by default, but support English when requested.' This imposes a language default rather than offering a neutral choice or explicit opt-in, which matches the language/locale policy violation category.

Hidden Instructions

High
Category
Prompt Injection
Content
---
name: hap-mongodb-slowlog-analysis
description: Analyze MongoDB 4.4.x slow logs from pasted slow-log text, uploaded log files, or mongodb.log content and produce practical query optimization advice, index recommendations, evidence-backed reasoning, and ready-to-run Mongo shell index commands. The skill is AI-first and should analyze logs directly in conversation without relying on local PowerShell by default. It should also be able to group repeated entries by namespace, deduplicate repeated query shapes, and summarize repeated patterns before giving advice. Only treat DOCX or PDF export as optional conversion steps that may require local tooling. Prefer Chinese output by default, but support English when requested. For HAP worksheet collections whose names start with ws, treat _id, utime, rowid, and ctime single-field indexes as existing defaults and never recommend recreating those single-field indexes. Treat status as a low-cardinality field with only 1 and 9, where 1 means active/in-use, and do not include status in recommended index definitions.
---
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal