Atlas / MCP servers / mongodb-js / MongoDB

MongoDBBLOCK

mcp/mongodb-js/mongodb-3

A Model Context Protocol server to connect to MongoDB databases and MongoDB Atlas Clusters.

Verdict
BLOCK
Grade
F
Trust score
55 /100
Exposed tools
43 26r · 13w · 4d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
1,137
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://insiders.vscode.dev/redirect/mcp/install?name=mongodb&inputs=%5B%7B%22id%22%3A%22connectionstring%22%2C%22type%22%3A%22promptString%22%2C%22description%22%3A%22MongoDB%20connection%20string%22%7D%5D&config=%7B%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22mongodb-mcp-server%22%2C%22--readOnly%22%5D%2C%22env%22%3A%7B%22MDBMCPCONNECTIONSTRING%22%3A%22%24%7Binput%3Aconnectionstring%7D%22%7D%7D) [![Install in Cursor](https://img.shields.io/badge/Cursor-InstallServer-1e1e1e?logo=data:image/svg%2bxml;base64,PHN2ZyBoZWlnaHQ9IjFlbSIgc3R5bGU9ImZsZXg6bm9uZTtsaW5lLWhlaWdodDoxIiB2aWV3Qm94PSIwIDAgMjQgMjQiIHdpZHRoPSIxZW0iCiAgICB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPgogICAgPHRpdGxlPkN1cnNvcjwvdGl0bGU+CiAgICA8cGF0aCBkPSJNMTEuOTI1IDI0bDEwLjQyNS02LTEwLjQyNS02TDEuNSAxOGwxMC40MjUgNnoiCiAgICAgICAgZmlsbD0idXJsKCNsb2JlLW

Read from source at commit ddedafa6e442OBSERVED · 2026-09-25
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mongodb-mcp-server --env MDB_MCP_API_CLIENT_ID=${MDB_MCP_API_CLIENT_ID} --env MDB_MCP_API_CLIENT_SECRET=${MDB_MCP_API_CLIENT_SECRET} --env MDB_MCP_CONNECTION_STRING=${MDB_MCP_CONNECTION_STRING} --env MDB_MCP_API_CLIENT_ID=${MDB_MCP_API_CLIENT_ID} -- npx -y [email protected]
claude-code (oci)
claude mcp add mongodb-mcp-server:3.0.4 --env MDB_MCP_API_CLIENT_ID=${MDB_MCP_API_CLIENT_ID} --env MDB_MCP_API_CLIENT_SECRET=${MDB_MCP_API_CLIENT_SECRET} --env MDB_MCP_CONNECTION_STRING=${MDB_MCP_CONNECTION_STRING} --env MDB_MCP_API_CLIENT_ID=${MDB_MCP_API_CLIENT_ID} -- docker run -i --rm docker.io/mongodb/mongodb-mcp-server:3.0.4:None
03

Exposed tools (43)

26 read · 13 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
aggregatewriteRun an aggregation against a MongoDB collection
aggregate-dbwriteRun an aggregation against a MongoDB database
atlas-local-connect-deploymentreadConnect to a MongoDB Atlas Local deployment and get back a connectionId to pass to the other MongoDB tools
collection-indexesreadDescribe the indexes for a collection
collection-schemareadDescribe the schema for a collection
collection-storage-sizereadGets the size of the collection
connectreadConnect to a MongoDB instance and get back a connectionId to pass to the other MongoDB tools. Each call establishes a new, independent connection — multiple connections can be active at the same time.
connectionNamereadOptional short label for the connection (stored slugified with a short suffix, e.g.
connectionStringreadMongoDB connection string (in the mongodb:// or mongodb+srv:// format)
countreadGets the number of documents in a MongoDB collection using db.collection.count() and query as an optional filter parameter
create-collectionwriteCreates a new collection in a database. If the database doesn
create-indexwriteCreate an index for a collection
db-statsreadReturns statistics that reflect the use state of a single database
delete-manydestructiveRemoves all documents that match the filter from a MongoDB collection
drop-collectiondestructiveRemoves a collection or view from the database. The method also removes any indexes associated with the dropped collection.
drop-databasedestructiveRemoves the specified database, deleting the associated data files
drop-indexdestructiveDrop an index for the provided database and collection.
dropTargetreadIf true, drops the target collection if it exists
explainreadReturns statistics describing the execution of the winning plan chosen by the query optimizer for the evaluated method
exportreadExport a query or aggregation results in the specified EJSON format.
exportTitlereadA short description to uniquely identify the export.
filterreadThe query filter, matching the syntax of the query argument of db.collection.find()
findwriteRun a find query against a MongoDB collection
insert-manywriteInsert an array of documents into a MongoDB collection. If the list of documents is above com.mongodb/maxRequestPayloadBytes, consider inserting them in batches.
limitreadThe maximum number of results to return
list-collectionsreadList all collections for a given database
list-knowledge-sourcesreadList available data sources in the MongoDB Assistant knowledge base. Use this to explore available data sources or to find search filter parameters to use in search-knowledge.
methodwriteThe method and its arguments to run
mock-project-toolreadMock tool
mongodb-logsreadReturns the most recent logged mongod events
newNamereadThe new name for the collection
pipelinewriteAn array of aggregation stages to execute. The first stage must be a database-level aggregation stage (one of
projectionreadThe projection, matching the syntax of the projection argument of db.collection.find()
queryreadA natural language query to search for in the MongoDB Assistant knowledge base. This should be a single question or a topic that is relevant to the user
rename-collectionwriteRenames a collection in a MongoDB database
responseBytesLimitreadThe maximum number of bytes to return in the response. This value is capped by the server
search-knowledgereadSearch for information in the MongoDB Assistant knowledge base. This includes official documentation, curated expert guidance, and other resources provided by MongoDB. Supports filtering by data source and version.
sortwriteA document, describing the sort order, matching the syntax of the sort argument of cursor.sort(). The keys of the object are the fields to sort on, while the values are the sort directions (1 for ascending, -1 for descending).
typereadThe type of logs to return. Global returns all recent log entries, while startupWarnings returns only warnings and errors from when the process started.
updatewriteAn update document describing the modifications to apply using update operator expressions
update-manywriteUpdates all documents that match the specified filter for a collection. If the list of documents is above com.mongodb/maxRequestPayloadBytes, consider updating them in batches.
upsertwriteControls whether to insert a new document if no documents match the filter
verbosityreadThe verbosity of the explain plan, defaults to queryPlanner. If the user wants to know how fast is a query in execution time, use executionStats. It supports all verbosities as defined in the MongoDB Driver.
04

Trust audit

BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (4 observation(s))
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/setup/src/aiTool.ts:295
exec(cmd, (error) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/mongodb-atlas-mcp-remote/src/testHelpers/mockRemote.ts:28
const instance = new MockRemote(`http://127.0.0.1:${port}`, server);
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
packages/integration-tests/src/common/connectionInfo.test.ts:54
const connectionStringWithSpecialChars = "mongodb+srv://user:p%40ssw%[email protected]/database";
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
packages/logging/src/diskLogger.test.ts:96
message: 'Failed to connect: "mongodb://admin:SuperSecretPass123@/db"',
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
packages/logging/src/redactingLoggerBase.test.ts:89
message: 'Failed to connect: "mongodb://admin:SuperSecretPass123@/db"',
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
packages/tools-mongodb/src/common/connectionEntry.test.ts:173
entry.connect({ connectionString: "mongodb+srv://dbadmin:Real$ecretPass9@" })
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/tools-atlas/src/tools/create/createDBUser.test.ts:116
const password = "LeakyS3cret-Passw0rd";
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/integration-tests/src/fixtures/server.key:1
-----BEGIN PRIVATE KEY-----
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/tools-atlas/src/helpers/redactSensitiveKeys.test.ts:19
sslClientAuthenticationKey: "-----BEGIN PRIVATE KEY-----",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/tools-atlas/src/helpers/redactSensitiveKeys.test.ts:29
expect(JSON.stringify(redacted)).not.toContain("-----BEGIN PRIVATE KEY-----");
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete-many, drop-collection, drop-database, drop-index
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/tools-atlas/src/tools/create/createAccessList.test.ts:73
const result = await exec({
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/tools-atlas/src/tools/create/createAccessList.test.ts:96
const result = await exec({
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/tools-atlas/src/tools/create/createAccessList.test.ts:113
await expect(exec({ projectId })).rejects.toThrow(ToolArgumentValidationError);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/tools-atlas/src/tools/create/createAccessList.test.ts:114
await expect(exec({ projectId })).rejects.toThrow(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/browser-tests/vitest.config.ts:34
reportsDirectory: "../../coverage/packages/browser-tests",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/integration-tests/src/build.test.ts:9
const projectRoot = path.resolve(currentDir, "../../..");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/integration-tests/src/tools/assistant/assistantHelpers.ts:1
import { setupIntegrationTest, defaultTestConfig } from "../../integrationHelpers.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/integration-tests/src/tools/assistant/assistantHelpers.ts:3
import type { IntegrationTest } from "../../integrationHelpers.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/integration-tests/src/tools/assistant/listKnowledgeSources.test.ts:7
} from "../../integrationHelpers.js";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:624
curl http://0.0.0.0:8080/health
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/integration-tests/src/transports/streamableHttp.test.ts:459
expect(runner["monitoringServer"]!.serverAddress).toEqual("http://127.0.0.1:3001");
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/integration-tests/src/transports/streamableHttp.test.ts:523
expect(runner["monitoringServer"]!.serverAddress).toEqual("http://127.0.0.1:3001");

Gates applied: no_behavioural_pass.

Audited 2026-09-25 · audit v0.4.1 · source sha ddedafa6e442full audit observations/trust-audit/mcp-server/mongodb-js__mongodb-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-25ddedafa6e442BLOCKF55first audit
06

Questions

What is the MongoDB MCP server?

A Model Context Protocol server to connect to MongoDB databases and MongoDB Atlas Clusters.

What tools does MongoDB expose?

43 in total: 26 read-only, 13 that write, and 4 that can delete or overwrite (delete-many, drop-collection, drop-database, drop-index). Every one is listed on this page with its risk.

Is MongoDB safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (55/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does MongoDB need?

It reads BRAINTRUST_API_KEY, BRAINTRUST_API_KEY_OVERRIDE, GROVE_API_KEY, MDB_API_CLIENT_SECRET, MDB_AZURE_OPEN_AI_API_KEY, MDB_GEMINI_API_KEY, MDB_GROVE_API_KEY, MDB_MCP_API_CLIENT_ID, MDB_MCP_API_CLIENT_SECRET, MDB_MCP_AZURE_CMK_KEY_IDENTIFIER, MDB_MCP_AZURE_CMK_KEY_VAULT_NAME and MDB_MCP_CONNECTION_STRING from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does MongoDB run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @mongodb-js/mcp-ui at 3.0.4.

How current is this page?

The grade is for one exact copy of the source (ddedafa6e442), read on 2026-09-25. The repository is watched and re-audited when it changes.

Advertisement