Atlas / MCP servers / furey / MongoDB Lens

MongoDB LensCAUTION

mcp/furey/mongodb-lens

๐Ÿƒ๐Ÿ”Ž MongoDB Lens: Full Featured MCP Server for MongoDB Databases

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
42 22r ยท 14w ยท 6d
Transport
stdio
License
MIT
Stars
207
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](./LICENSE) [](https://hub.docker.com/r/furey/mongodb-lens) [](https://www.npmjs.com/package/mongodb-lens) [](https://www.buymeacoffee.com/furey)

MongoDB Lens is a local Model Context Protocol (MCP) server with full featured access to MongoDB databases using natural language via LLMs to perform queries, run aggregations, optimize performance, and more.

Contents

  • Quick Start
  • Features
  • Installation
  • Configuration
  • Client Setup
  • Data Protection
  • Tutorial
  • Test Suite
  • Disclaimer
  • Support

Quick Start

  • Install MongoDB Lens
  • Configure MongoDB Lens
  • Set up your MCP Client (e.g. Claude Desktop, Cursor, etc)
  • Explore your MongoDB databases with natural language queries

Features

  • Tools
  • Resources
  • Prompts
  • Other

Tools

Read from source at commit ac94b5c15569OBSERVED ยท 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source โ€” not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mongodb-lens --env CONFIG_DISABLE_DESTRUCTIVE_OPERATION_TOKENS=${CONFIG_DISABLE_DESTRUCTIVE_OPERATION_TOKENS} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mongodb-lens": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CONFIG_DISABLE_DESTRUCTIVE_OPERATION_TOKENS": "${CONFIG_DISABLE_DESTRUCTIVE_OPERATION_TOKENS}"
      }
    }
  }
}
03

Exposed tools (42)

22 read ยท 14 write ยท 6 destructive. Blast radius: 6 tools can delete or overwrite โ€” an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add-connection-aliaswriteAdd a new MongoDB connection alias
aggregate-datawriteRun aggregation pipelines
analyze-query-patternsreadAnalyze query patterns and suggest optimizations
analyze-schemareadAutomatically infer schema from collection
bulk-operationsreadPerform bulk inserts, updates, or deletes
clear-cachedestructiveClear memory caches to ensure fresh data
collation-queryreadFind documents with language-specific collation rules
compare-schemasreadCompare schemas between two collections
connect-mongodbreadConnect to a different MongoDB URI or alias
connect-originalreadConnect back to the original MongoDB URI used at startup
count-documentsreadCount documents with optional filter
create-collectionwriteCreate a new collection with options
create-databasewriteCreate a new MongoDB database with option to switch
create-indexwriteCreate new index on collection
create-timeserieswriteCreate a time series collection for temporal data
create-userwriteCreate a new database user
current-databasereadGet the name of the current database
delete-documentdestructiveDelete document(s) (requires confirmation)
distinct-valuesreadGet unique values for a field
drop-collectiondestructiveDrop a collection (requires confirmation)
drop-databasedestructiveDrop a database (requires confirmation)
drop-indexdestructiveDrop an existing index from a collection
drop-userdestructiveDrop an existing database user
explain-queryreadAnalyze query performance
export-datareadExport query results to formatted JSON or CSV
find-documentswriteRun queries with filters and projections
generate-schema-validatorreadGenerate a JSON Schema validator for a collection
geo-querywriteRun geospatial queries with various operators
get-statsreadGet database or collection statistics
gridfs-operationreadManage large files with GridFS
insert-documentwriteInsert one or multiple documents into a collection
list-collectionsreadList collections in the current database
list-connectionsreadList all configured MongoDB connection aliases
list-databasesreadList all accessible MongoDB databases
rename-collectionwriteRename an existing collection
shard-statusreadGet sharding status for database or collections
text-searchreadPerform full-text search across text-indexed fields
transactionwriteExecute multiple operations in a single transaction
update-documentwriteUpdate specific documents in a collection
use-databasereadSwitch to a specific database
validate-collectionwriteRun validation on a collection to check for inconsistencies
watch-changesreadWatch for changes in a collection using change streams
04

Trust audit

CAUTIONgrade B ยท trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

MEDIUMInsecure crypto ยท crypto.weak_random ยท CWE-327, CWE-338
mongodb-lens.js:5429
return String(Math.floor(Math.random() * maxToken)).padStart(config.security.tokenLength, '0')
MEDIUMFilesystem / path ยท mcp.destructive_tools ยท CWE-22, CWE-59
clear-cache, delete-document, drop-collection, drop-database, drop-index, drop-user
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain ยท supply.unpinned ยท CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, cross-env, lodash, mongodb, strip-json-comments, zod, mongodb-memory-server
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection ยท prompt.credential_read ยท CWE-94, CWE-1427
README.md:875
Using read-only credentials is a simple yet effective way to enforce security boundaries, especially when you're poking around schemas or running ad-hoc queries.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-06 ยท audit v0.4.1 ยท source sha ac94b5c15569full audit observations/trust-audit/mcp-server/furey__mongodb-lens.json ยท Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06ac94b5c15569CAUTIONB89first audit
06

Questions

What is the MongoDB Lens MCP server?

๐Ÿƒ๐Ÿ”Ž MongoDB Lens: Full Featured MCP Server for MongoDB Databases

What tools does MongoDB Lens expose?

42 in total: 22 read-only, 14 that write, and 6 that can delete or overwrite (clear-cache, delete-document, drop-collection, drop-database, drop-index). Every one is listed on this page with its risk.

Is MongoDB Lens safe to connect to an agent?

With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does MongoDB Lens need?

It reads CONFIG_DISABLE_DESTRUCTIVE_OPERATION_TOKENS from the environment. Give it a token scoped to the least it needs โ€” an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does MongoDB Lens run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mongodb-lens at 9.1.4.

How current is this page?

The grade is for one exact copy of the source (ac94b5c15569), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement