couchbase-eventing
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill documents the use of official Couchbase administrative CLI tools (e.g.,
admin_eventing_deploy_function) for lifecycle management. These are standard platform tools used for their intended purpose. - [DATA_EXFILTRATION]: The skill explains the use of
curl()for external HTTP calls but emphasizes the requirement for URL bindings. This platform feature ensures that the agent can only communicate with pre-configured hostnames, preventing arbitrary data exfiltration to unauthorized domains. - [INDIRECT_PROMPT_INJECTION]: The skill describes an architecture for processing document mutations which acts as an ingestion point for untrusted data.
- Ingestion points: Document mutations processed by
OnUpdate(doc, meta)inreferences/function-authoring.md. - Boundary markers: The skill demonstrates filtering logic based on document metadata (e.g.,
if (doc.type !== "order") return;). - Capability inventory: Handlers can perform database writes via KV bindings, execute SQL++ queries via
N1QL(), and make network requests viacurl(). - Sanitization: The skill provides examples of parameterized SQL++ queries (e.g.,
WHERE o.customer_id = $customer_id) to prevent injection attacks. - [PRIVILEGE_ESCALATION]: The documentation includes a dedicated section on RBAC requirements that explicitly warns against granting overly broad permissions and recommends the principle of least privilege for the Eventing service account.
Audit Metadata