Mongo Scout Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mongo Scout Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Scout your MongoDB databases with AI - A production-ready Model Context Protocol server with built-in safety features, live monitoring, and data quality tools.
You ask:
"Anything unusual happening with order volume this month?"
Mongo Scout returns:
ordersStatistics (last 30 days)
| Metric | Value |
|---|---|
| Daily Average | 2,847 documents |
| Standard Deviation | 412 |
| Min / Max | 1,923 / 3,601 |
Anomalies Detected
Recommendations
That's detectVolumeAnomalies — one of 50 tools covering exploration, querying, diagnostics, monitoring, data quality, and safe writes.
claude mcp add mongo-scout -- npx -y mongo-scout-mcp mongodb://localhost:27017 mydbThen ask: "What collections do I have and what do their schemas look like?"
<details> <summary>Claude Desktop</summary>
Add to your Claude Desktop config (~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
{
"mcpServers": {
"mongo-scout": {
"command": "npx",
"args": ["-y", "mongo-scout-mcp", "mongodb://localhost:27017", "mydb"],
"type": "stdio"
}
}
}</details>
<details> <summary>Cursor / VS Code</summary>
Add to your MCP settings:
{
"mongo-scout": {
"command": "npx",
"args": ["-y", "mongo-scout-mcp", "mongodb://localhost:27017", "mydb"]
}
}</details>
<details> <summary>Read-Only vs Read-Write</summary>
The server runs in read-only mode by default. For write operations, run a separate instance:
{
"mcpServers": {
"mongo-scout-readonly": {
"command": "npx",
"args": ["-y", "mongo-scout-mcp", "--read-only", "mongodb://localhost:27017", "mydb"],
"type": "stdio"
},
"mongo-scout-readwrite": {
"command": "npx",
"args": ["-y", "mongo-scout-mcp", "--read-write", "mongodb://localhost:27017", "mydb_dev"],
"type": "stdio"
}
}
}</details>
listDatabases — all databases in the instancegetDatabaseStats — storage and performance statisticslistCollections — collections in the current databasegetCollectionStats — size, document count, index detailsinferSchema — schema inference from sampled documentsfind — query documents with filtering, sorting, projectionaggregate — run aggregation pipelinescount — count documents matching a querydistinct — unique values for a fieldtextSearch — full-text search across indexed fieldsexplainQuery — query execution plan analysisdetectVolumeAnomalies — unusual patterns in document volumeanalyzeQueryPerformance — query optimization using explain plansgetServerStatus — server performance metricsgetCurrentOperations — currently running operationsgetConnectionPoolStats — connection pool healthgetProfilerStats — profiler data and slow operationsgetLiveMetrics — real-time metrics with continuous updatesgetHottestCollections — collections with highest activitygetCollectionMetrics — detailed per-collection metricsgetSlowestOperations — slow query trackingrunAdminCommand — execute admin commandsfindDuplicates — duplicate documents by field combinationfindOrphans — orphaned references across collectionsfindMissingFields — documents missing required fieldsfindInconsistentTypes — type inconsistencies across documentsvalidateDocuments — custom validation with MongoDB $exprexploreRelationships — multi-hop relationship traversalfindRecent — documents within a time windowfindInTimeRange — date range queries with optional groupinglistIndexes — all indexes for a collectioncreateIndex — create new indexesdropIndex — remove indexesexportCollection — JSON, JSONL, or CSVcloneCollection — clone with filtering and index copyingpreviewUpdate / previewDelete — see what would change before committingpreviewBulkWrite — preview bulk operationsinsertOne / insertMany — insert documentsupdateOne / updateMany — update with dryRun and maxDocuments limitsreplaceOne — replace a single documentfindOneAndUpdate — find and update atomicallydeleteOne / deleteMany — delete with dryRun and maxDocuments limitsbulkWrite — multiple write operations in one callrenameField — rename fields with dry-run and index migrationcreateCollection / dropCollection — collection management"What collections do I have and what's the schema of users?"
listCollections()
inferSchema({ collection: "users", sampleSize: 50 })"Find duplicate emails in the users collection."
findDuplicates({ collection: "users", fields: ["email"], options: { limit: 100 } })"Show me order volume anomalies over the last month."
detectVolumeAnomalies({ collection: "orders", timestampField: "createdAt", options: { groupBy: "day", lookbackPeriods: 30 } })"What's happening on the server right now?"
getServerStatus()
getCurrentOperations()
getHottestCollections({ limit: 5, sampleDuration: 5000 })"Find orders that reference deleted users."
findOrphans({ collection: "orders", localField: "userId", foreignCollection: "users", foreignField: "_id" })"Export the products collection as CSV."
exportCollection({ collection: "products", options: { format: "csv", flatten: true } })| Variable | Default | Description |
|---|---|---|
ENABLE_LOGGING | false | Enable file logging |
LOG_DIR | ./logs | Log file directory |
CLI flags: --read-only (default), --read-write, --mode <mode>
File logging is disabled by default. Set ENABLE_LOGGING=true to enable. Two log files are created in LOG_DIR:
Connection strings are automatically redacted in all output.
Both formats accepted:
{ "_id": { "$oid": "507f1f77bcf86cd799439011" } }
{ "_id": "507f1f77bcf86cd799439011" }git clone https://github.com/bluwork/mongo-scout-mcp.git
cd mongo-scout-mcp
pnpm install
pnpm build
pnpm testApache-2.0
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.