v0.2.0 · live
CAPFRAME
← leaderboard/MongoDB MCP/tool · mongodb-logs
§ toolsandboxMongoDB MCP

mongodb-logs

on npm:mongodb-mcp-server@1.11.0

Severity

critical0
high1
medium0
low0
info0

1 finding on this tool

  1. highexcessive agencyf-r4-mongodb_logs

    Tool `mongodb-logs` accepts an unbounded monetary / quota value

    The numeric parameter(s) `limit` have a money/quota-shaped name but no `maximum` constraint. An LLM tricked by indirect-injection can call the tool with arbitrarily large values.

    fix: Add a `maximum` (and ideally `minimum`) to each money/quota numeric, OR enforce the cap via a capframe-bind `--limit` caveat at the agent boundary.

    OWASP LLM08NIST MANAGE-2.2ATLAS T0051CAST-01

About this tool

mongodb-logs is one of 25 tools exposed by MongoDB MCP. The server scored 4/100 overall against the capframe rule engine (source: sandbox). Last scanned 2026-07-20.

The findings above are emitted by the public capframe.findings.v1 schema. Disagree with one? Open an issue.