couchbase-ai-applications

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill provides prompt templates for RAG (Retrieval-Augmented Generation) that interpolate external database content directly into system messages. This architecture creates a surface for indirect prompt injection, as malicious data stored in the database could potentially influence the agent's behavior.
  • Ingestion points: Data is ingested through vector search results and concatenated into prompts in references/rag-patterns.md and references/framework-integration.md.
  • Boundary markers: The templates use text-based separators (e.g., 'Sources:') and identifiers like '[Source N]' but do not implement robust isolation or formal delimiters (such as XML tags or JSON schemas) to prevent the model from obeying instructions embedded in the retrieved text.
  • Capability inventory: The skill facilitates read and write access to Couchbase collections (via mutate_in and cb_fts_search) and integration with external LLM APIs (OpenAI, Cohere).
  • Sanitization: The provided implementation examples do not demonstrate sanitization, filtering, or validation of the retrieved content before it is processed by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 08:30 PM
Security Audit — agent-trust-hub — couchbase-ai-applications