MongoDB LensCAUTION
๐๐ MongoDB Lens: Full Featured MCP Server for MongoDB Databases
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](./LICENSE) [](https://hub.docker.com/r/furey/mongodb-lens) [](https://www.npmjs.com/package/mongodb-lens) [](https://www.buymeacoffee.com/furey)
MongoDB Lens is a local Model Context Protocol (MCP) server with full featured access to MongoDB databases using natural language via LLMs to perform queries, run aggregations, optimize performance, and more.
Contents
- Quick Start
- Features
- Installation
- Configuration
- Client Setup
- Data Protection
- Tutorial
- Test Suite
- Disclaimer
- Support
Quick Start
- Install MongoDB Lens
- Configure MongoDB Lens
- Set up your MCP Client (e.g. Claude Desktop, Cursor, etc)
- Explore your MongoDB databases with natural language queries
Features
- Tools
- Resources
- Prompts
- Other
Tools
- `add-connection-alias`: Add a new MongoDB connection alias
- `aggregate-data`: Execute aggregation pipelines
- `analyze-query-patterns`: A
ac94b5c15569OBSERVED ยท 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source โ not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mongodb-lens --env CONFIG_DISABLE_DESTRUCTIVE_OPERATION_TOKENS=${CONFIG_DISABLE_DESTRUCTIVE_OPERATION_TOKENS} -- npx -y [email protected]{
"mcpServers": {
"mongodb-lens": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"CONFIG_DISABLE_DESTRUCTIVE_OPERATION_TOKENS": "${CONFIG_DISABLE_DESTRUCTIVE_OPERATION_TOKENS}"
}
}
}
}Exposed tools (42)
22 read ยท 14 write ยท 6 destructive. Blast radius: 6 tools can delete or overwrite โ an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add-connection-alias | write | Add a new MongoDB connection alias |
aggregate-data | write | Run aggregation pipelines |
analyze-query-patterns | read | Analyze query patterns and suggest optimizations |
analyze-schema | read | Automatically infer schema from collection |
bulk-operations | read | Perform bulk inserts, updates, or deletes |
clear-cache | destructive | Clear memory caches to ensure fresh data |
collation-query | read | Find documents with language-specific collation rules |
compare-schemas | read | Compare schemas between two collections |
connect-mongodb | read | Connect to a different MongoDB URI or alias |
connect-original | read | Connect back to the original MongoDB URI used at startup |
count-documents | read | Count documents with optional filter |
create-collection | write | Create a new collection with options |
create-database | write | Create a new MongoDB database with option to switch |
create-index | write | Create new index on collection |
create-timeseries | write | Create a time series collection for temporal data |
create-user | write | Create a new database user |
current-database | read | Get the name of the current database |
delete-document | destructive | Delete document(s) (requires confirmation) |
distinct-values | read | Get unique values for a field |
drop-collection | destructive | Drop a collection (requires confirmation) |
drop-database | destructive | Drop a database (requires confirmation) |
drop-index | destructive | Drop an existing index from a collection |
drop-user | destructive | Drop an existing database user |
explain-query | read | Analyze query performance |
export-data | read | Export query results to formatted JSON or CSV |
find-documents | write | Run queries with filters and projections |
generate-schema-validator | read | Generate a JSON Schema validator for a collection |
geo-query | write | Run geospatial queries with various operators |
get-stats | read | Get database or collection statistics |
gridfs-operation | read | Manage large files with GridFS |
insert-document | write | Insert one or multiple documents into a collection |
list-collections | read | List collections in the current database |
list-connections | read | List all configured MongoDB connection aliases |
list-databases | read | List all accessible MongoDB databases |
rename-collection | write | Rename an existing collection |
shard-status | read | Get sharding status for database or collections |
text-search | read | Perform full-text search across text-indexed fields |
transaction | write | Execute multiple operations in a single transaction |
update-document | write | Update specific documents in a collection |
use-database | read | Switch to a specific database |
validate-collection | write | Run validation on a collection to check for inconsistencies |
watch-changes | read | Watch for changes in a collection using change streams |
Trust audit
CAUTIONgrade B ยท trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
return String(Math.floor(Math.random() * maxToken)).padStart(config.security.tokenLength, '0')
clear-cache, delete-document, drop-collection, drop-database, drop-index, drop-user
@modelcontextprotocol/sdk, cross-env, lodash, mongodb, strip-json-comments, zod, mongodb-memory-server
Using read-only credentials is a simple yet effective way to enforce security boundaries, especially when you're poking around schemas or running ad-hoc queries.
Gates applied: no_behavioural_pass.
ac94b5c15569full audit observations/trust-audit/mcp-server/furey__mongodb-lens.json ยท Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | ac94b5c15569 | CAUTION | B | 89 | first audit |
Questions
What is the MongoDB Lens MCP server?
๐๐ MongoDB Lens: Full Featured MCP Server for MongoDB Databases
What tools does MongoDB Lens expose?
42 in total: 22 read-only, 14 that write, and 6 that can delete or overwrite (clear-cache, delete-document, drop-collection, drop-database, drop-index). Every one is listed on this page with its risk.
Is MongoDB Lens safe to connect to an agent?
With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does MongoDB Lens need?
It reads CONFIG_DISABLE_DESTRUCTIVE_OPERATION_TOKENS from the environment. Give it a token scoped to the least it needs โ an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does MongoDB Lens run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mongodb-lens at 9.1.4.
How current is this page?
The grade is for one exact copy of the source (ac94b5c15569), read on 2026-10-06. The repository is watched and re-audited when it changes.