Back to plugin

Security audit

MongoDB

Security checks for vulnerabilities and agentic risk

Overview

The plugin appears to be a coherent read-only MongoDB integration, but it can still read and return data reachable through the MongoDB connection string you provide.

This looks appropriate for a read-only MongoDB plugin. Before installing, create a dedicated read-only MongoDB credential with the narrowest database and collection access possible, verify you are comfortable with the agent seeing returned sample documents, and install from the expected npm package/version.

Static analysis

No suspicious patterns detected.