couchbase-coding-standards
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to perform code reviews and process user-supplied application code, which represents a potential injection surface for malicious code snippets to influence agent behavior. However, the skill explicitly provides defensive instructions to mitigate such risks in the code being reviewed.
- Ingestion points: Processes user-provided source code for review and suggestions as described in
SKILL.md. - Boundary markers: No explicit delimiters are provided in the reference files for separating user code from review instructions.
- Capability inventory: The skill itself does not request any tool permissions or execution capabilities.
- Sanitization: Not applicable as the skill contains static reference guidelines.
- [SAFE]: The skill provides security-positive guidance, such as mandating parameterization for SQL++ queries to prevent injection and advocating for the use of environment variables or secrets managers for credentials.
Audit Metadata