Atlas / MCP servers / kiliczsh / Mongo

MongoCAUTION

mcp/kiliczsh/mongo

A Model Context Protocol Server for MongoDB

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
12 7r · 5w · 0d
Transport
—
License
MIT
Stars
281
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that lets AI assistants work with your MongoDB databases. It exposes your collections, infers their schemas, and runs queries, aggregations, and writes through a standard interface — so tools like Claude Desktop and Cursor can read and reason about your data.

Demo

[](https://www.youtube.com/watch?v=FI-oE_voCpA)

Why use it

  • Talk to your database in plain language — the assistant discovers your collections and their shape automatically.
  • Safe by default — turn on read-only mode to let an assistant explore without any risk of changing data.
  • Works everywhere — connects to standalone, replica set, sharded, and Atlas deployments, over plain or TLS connections.

Key Features

  • Read-Only Mode — blocks every write path (insert, update, index creation, and aggregation stages like $out/$merge that could modify data).
  • Smart ObjectId Handling — configurable auto/none/force conversion of 24-character hex strings to ObjectIds.
  • Schema Inference — automatic collection schema detection from document samples.
  • Query & Aggregation — full query and aggregation pipeline support, with optional explain plans.
  • Write Operations — insert, update, and index creation (when read-only mode is off).
  • Time Conversion — a convertTime helper turns Unix timestamps and date strings into UTC/GMT/ISO, so date queries stay unambiguous across timezones.
  • Progress & Cancellation — long operations report progress and can be cancelled mid-flight.
  • Two Transports — run locally over stdio, or expose an HTTP endpoint for remote access.

Requirements

  • Node.js 20 or newer

Quick Start

Read from source at commit ff733a6ceb3dOBSERVED · 2026-10-05
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-mongo-server --env MCP_HTTP_AUTH_TOKEN=${MCP_HTTP_AUTH_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-mongo-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "MCP_HTTP_AUTH_TOKEN": "${MCP_HTTP_AUTH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (12)

7 read · 5 write · 0 destructive.

ToolRiskDescription
aggregatewriteExecute a MongoDB aggregation pipeline with optional execution plan analysis
analyze_collectionreadAnalyze a MongoDB collection structure and contents
collectionreadName of the collection to analyze
convertTimereadConvert a Unix timestamp or date string to multiple formats (UTC ISO 8601, GMT, Unix seconds/milliseconds) and report the server
countreadCount documents in a collection matching a query
createIndexwriteCreate one or more indexes on a MongoDB collection
insertwriteInsert one or more documents into a MongoDB collection
listCollectionsreadList all collections in the MongoDB database
mongodb_queryreadTemplate for constructing MongoDB queries
querywriteExecute a MongoDB query with optional execution plan analysis
serverInforeadGet MongoDB server information including version, storage engine, and other details
updatewriteUpdate documents in a MongoDB collection
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (3)

HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docker-compose.yml:8
- MCP_MONGODB_URI=mongodb://muhammed:kilic@localhost:27017/database
LOWInventory / provenance · inv.hidden_file · CWE-1104
.npmrc-github
.npmrc-github
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/express, @modelcontextprotocol/node, @modelcontextprotocol/server, mongodb, @biomejs/biome, @modelcontextprotocol/client, @modelcontextprotocol/inspector, @types/node
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-05 · audit v0.4.1 · source sha ff733a6ceb3dfull audit observations/trust-audit/mcp-server/kiliczsh__mongo.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-05ff733a6ceb3dCAUTIONB89first audit
06

Questions

What is the Mongo MCP server?

A Model Context Protocol Server for MongoDB

What tools does Mongo expose?

12 in total: 7 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Mongo safe to connect to an agent?

With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Mongo need?

It reads MCP_HTTP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (ff733a6ceb3d), read on 2026-10-05. The repository is watched and re-audited when it changes.

Advertisement