couchbase-columnar

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of data from external sources including operational clusters and cloud storage (S3, Azure Blob, GCS). This creates an attack surface where maliciously crafted data could potentially influence agent behavior.
  • Ingestion points: Data enters the context via managed DCP pipelines from operational clusters or directly from files in object storage (references/architecture.md, references/usage.md).
  • Boundary markers: The skill does not provide specific instructions for delimiting or sanitizing external content within its SQL++ examples.
  • Capability inventory: The skill enables SQL++ querying capabilities including aggregations, JOINs, and window functions on large datasets.
  • Sanitization: Relies on default database engine behavior; no specific input validation or sanitization logic is included in the instructions.
  • [EXTERNAL_DOWNLOADS]: The instructions refer to downloading JDBC and ODBC drivers from the official Couchbase documentation website (docs.couchbase.com) for BI tool integration. This is a standard operation for the documented service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 05:55 PM
Security Audit — agent-trust-hub — couchbase-columnar