MongoDBBLOCK
A Model Context Protocol server to connect to MongoDB databases and MongoDB Atlas Clusters.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://insiders.vscode.dev/redirect/mcp/install?name=mongodb&inputs=%5B%7B%22id%22%3A%22connectionstring%22%2C%22type%22%3A%22promptString%22%2C%22description%22%3A%22MongoDB%20connection%20string%22%7D%5D&config=%7B%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22mongodb-mcp-server%22%2C%22--readOnly%22%5D%2C%22env%22%3A%7B%22MDBMCPCONNECTIONSTRING%22%3A%22%24%7Binput%3Aconnectionstring%7D%22%7D%7D) [
26 read · 13 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
aggregate | write | Run an aggregation against a MongoDB collection |
aggregate-db | write | Run an aggregation against a MongoDB database |
atlas-local-connect-deployment | read | Connect to a MongoDB Atlas Local deployment and get back a connectionId to pass to the other MongoDB tools |
collection-indexes | read | Describe the indexes for a collection |
collection-schema | read | Describe the schema for a collection |
collection-storage-size | read | Gets the size of the collection |
connect | read | Connect to a MongoDB instance and get back a connectionId to pass to the other MongoDB tools. Each call establishes a new, independent connection — multiple connections can be active at the same time. |
connectionName | read | Optional short label for the connection (stored slugified with a short suffix, e.g. |
connectionString | read | MongoDB connection string (in the mongodb:// or mongodb+srv:// format) |
count | read | Gets the number of documents in a MongoDB collection using db.collection.count() and query as an optional filter parameter |
create-collection | write | Creates a new collection in a database. If the database doesn |
create-index | write | Create an index for a collection |
db-stats | read | Returns statistics that reflect the use state of a single database |
delete-many | destructive | Removes all documents that match the filter from a MongoDB collection |
drop-collection | destructive | Removes a collection or view from the database. The method also removes any indexes associated with the dropped collection. |
drop-database | destructive | Removes the specified database, deleting the associated data files |
drop-index | destructive | Drop an index for the provided database and collection. |
dropTarget | read | If true, drops the target collection if it exists |
explain | read | Returns statistics describing the execution of the winning plan chosen by the query optimizer for the evaluated method |
export | read | Export a query or aggregation results in the specified EJSON format. |
exportTitle | read | A short description to uniquely identify the export. |
filter | read | The query filter, matching the syntax of the query argument of db.collection.find() |
find | write | Run a find query against a MongoDB collection |
insert-many | write | Insert an array of documents into a MongoDB collection. If the list of documents is above com.mongodb/maxRequestPayloadBytes, consider inserting them in batches. |
limit | read | The maximum number of results to return |
list-collections | read | List all collections for a given database |
list-knowledge-sources | read | List available data sources in the MongoDB Assistant knowledge base. Use this to explore available data sources or to find search filter parameters to use in search-knowledge. |
method | write | The method and its arguments to run |
mock-project-tool | read | Mock tool |
mongodb-logs | read | Returns the most recent logged mongod events |
newName | read | The new name for the collection |
pipeline | write | An array of aggregation stages to execute. The first stage must be a database-level aggregation stage (one of |
projection | read | The projection, matching the syntax of the projection argument of db.collection.find() |
query | read | A natural language query to search for in the MongoDB Assistant knowledge base. This should be a single question or a topic that is relevant to the user |
rename-collection | write | Renames a collection in a MongoDB database |
responseBytesLimit | read | The maximum number of bytes to return in the response. This value is capped by the server |
search-knowledge | read | Search for information in the MongoDB Assistant knowledge base. This includes official documentation, curated expert guidance, and other resources provided by MongoDB. Supports filtering by data source and version. |
sort | write | A document, describing the sort order, matching the syntax of the sort argument of cursor.sort(). The keys of the object are the fields to sort on, while the values are the sort directions (1 for ascending, -1 for descending). |
type | read | The type of logs to return. Global returns all recent log entries, while startupWarnings returns only warnings and errors from when the process started. |
update | write | An update document describing the modifications to apply using update operator expressions |
update-many | write | Updates all documents that match the specified filter for a collection. If the list of documents is above com.mongodb/maxRequestPayloadBytes, consider updating them in batches. |
upsert | write | Controls whether to insert a new document if no documents match the filter |
verbosity | read | The verbosity of the explain plan, defaults to queryPlanner. If the user wants to know how fast is a query in execution time, use executionStats. It supports all verbosities as defined in the MongoDB Driver. |
Trust audit
BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (4 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
exec(cmd, (error) => {const instance = new MockRemote(`http://127.0.0.1:${port}`, server);const connectionStringWithSpecialChars = "mongodb+srv://user:p%40ssw%[email protected]/database";
message: 'Failed to connect: "mongodb://admin:SuperSecretPass123@/db"',
message: 'Failed to connect: "mongodb://admin:SuperSecretPass123@/db"',
entry.connect({ connectionString: "mongodb+srv://dbadmin:Real$ecretPass9@" })const password = "LeakyS3cret-Passw0rd";
-----BEGIN PRIVATE KEY-----
sslClientAuthenticationKey: "-----BEGIN PRIVATE KEY-----",
expect(JSON.stringify(redacted)).not.toContain("-----BEGIN PRIVATE KEY-----");delete-many, drop-collection, drop-database, drop-index
.prettierignore
.prettierrc.json
const result = await exec({const result = await exec({await expect(exec({ projectId })).rejects.toThrow(ToolArgumentValidationError);await expect(exec({ projectId })).rejects.toThrow(reportsDirectory: "../../coverage/packages/browser-tests",
const projectRoot = path.resolve(currentDir, "../../..");
import { setupIntegrationTest, defaultTestConfig } from "../../integrationHelpers.js";import type { IntegrationTest } from "../../integrationHelpers.js";} from "../../integrationHelpers.js";
curl http://0.0.0.0:8080/health
expect(runner["monitoringServer"]!.serverAddress).toEqual("http://127.0.0.1:3001");expect(runner["monitoringServer"]!.serverAddress).toEqual("http://127.0.0.1:3001");Gates applied: no_behavioural_pass.
ddedafa6e442full audit observations/trust-audit/mcp-server/mongodb-js__mongodb-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-25 | ddedafa6e442 | BLOCK | F | 55 | first audit |
Questions
What is the MongoDB MCP server?
A Model Context Protocol server to connect to MongoDB databases and MongoDB Atlas Clusters.
What tools does MongoDB expose?
43 in total: 26 read-only, 13 that write, and 4 that can delete or overwrite (delete-many, drop-collection, drop-database, drop-index). Every one is listed on this page with its risk.
Is MongoDB safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (55/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does MongoDB need?
It reads BRAINTRUST_API_KEY, BRAINTRUST_API_KEY_OVERRIDE, GROVE_API_KEY, MDB_API_CLIENT_SECRET, MDB_AZURE_OPEN_AI_API_KEY, MDB_GEMINI_API_KEY, MDB_GROVE_API_KEY, MDB_MCP_API_CLIENT_ID, MDB_MCP_API_CLIENT_SECRET, MDB_MCP_AZURE_CMK_KEY_IDENTIFIER, MDB_MCP_AZURE_CMK_KEY_VAULT_NAME and MDB_MCP_CONNECTION_STRING from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does MongoDB run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @mongodb-js/mcp-ui at 3.0.4.
How current is this page?
The grade is for one exact copy of the source (ddedafa6e442), read on 2026-09-25. The repository is watched and re-audited when it changes.