Mongoose Mongodb Security

Security audit for MongoDB and Mongoose-based applications including NoSQL operator injection ($where, $ne, $gt), mass assignment via spreading into Model.create, schema validation bypass, aggregation pipeline safety, lean() vs hydrated query exposure, missing tenant scoping, and MongoDB connection string handling. Use this skill whenever the user mentions MongoDB, Mongoose, mongoose.Schema, Model.create, Model.findOne, aggregate pipeline, $where, $regex, MongoClient, or asks "audit my MongoDB queries", "Mongoose security", "NoSQL injection". Trigger when the codebase contains `mongoose`, `mongodb`, or `@mongodb/*` in package.json.

hlsitechio 2537c68 7.7 KB Updated

File contents

hlsitechio/claude-skills-security/tree/main/appsec-stack-pack/mongoose-mongodb-security commit 2537c6893a

Frequently asked questions

npx skillmds@latest add hlsitechio/mongoose-mongodb-security