couchbase-eventing

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents the use of official Couchbase administrative CLI tools (e.g., admin_eventing_deploy_function) for lifecycle management. These are standard platform tools used for their intended purpose.
  • [DATA_EXFILTRATION]: The skill explains the use of curl() for external HTTP calls but emphasizes the requirement for URL bindings. This platform feature ensures that the agent can only communicate with pre-configured hostnames, preventing arbitrary data exfiltration to unauthorized domains.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes an architecture for processing document mutations which acts as an ingestion point for untrusted data.
  • Ingestion points: Document mutations processed by OnUpdate(doc, meta) in references/function-authoring.md.
  • Boundary markers: The skill demonstrates filtering logic based on document metadata (e.g., if (doc.type !== "order") return;).
  • Capability inventory: Handlers can perform database writes via KV bindings, execute SQL++ queries via N1QL(), and make network requests via curl().
  • Sanitization: The skill provides examples of parameterized SQL++ queries (e.g., WHERE o.customer_id = $customer_id) to prevent injection attacks.
  • [PRIVILEGE_ESCALATION]: The documentation includes a dedicated section on RBAC requirements that explicitly warns against granting overly broad permissions and recommends the principle of least privilege for the Eventing service account.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 05:56 PM
Security Audit — agent-trust-hub — couchbase-eventing