couchbase-ai-applications
Warn
Audited by Snyk on Jul 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The skill’s runtime RAG workflow (retrieve top-k chunks/memories from Couchbase and then “Pass retrieved chunks + user query to the LLM”) can inject outsider-authored text because retrieved
chunk_text/ memorycontentmay originate from documents or conversations the operating user did not author.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata