couchbase-ai-applications
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill provides prompt templates for RAG (Retrieval-Augmented Generation) that interpolate external database content directly into system messages. This architecture creates a surface for indirect prompt injection, as malicious data stored in the database could potentially influence the agent's behavior.
- Ingestion points: Data is ingested through vector search results and concatenated into prompts in
references/rag-patterns.mdandreferences/framework-integration.md. - Boundary markers: The templates use text-based separators (e.g., 'Sources:') and identifiers like '[Source N]' but do not implement robust isolation or formal delimiters (such as XML tags or JSON schemas) to prevent the model from obeying instructions embedded in the retrieved text.
- Capability inventory: The skill facilitates read and write access to Couchbase collections (via
mutate_inandcb_fts_search) and integration with external LLM APIs (OpenAI, Cohere). - Sanitization: The provided implementation examples do not demonstrate sanitization, filtering, or validation of the retrieved content before it is processed by the LLM.
Audit Metadata