couchbase-mobile
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No evidence of instructions designed to bypass safety filters or override agent behavior was found. The guidance is purely technical and focused on Couchbase Mobile application development.
- [CREDENTIALS_UNSAFE]: The code snippets use generic placeholders for demonstration purposes (e.g., 'alice', 'password', 'sessionToken'). No hardcoded production credentials, API keys, or private secrets were found. The skill correctly recommends the use of Session Authentication for production environments.
- [DATA_EXFILTRATION]: No suspicious network operations or unauthorized data access patterns were detected. The network operations described are limited to standard Couchbase Lite synchronization protocols with designated service endpoints.
- [EXTERNAL_DOWNLOADS]: The skill mentions official Couchbase resources and platform-specific SDKs (iOS, Android, React Native, .NET, Python). All references are to well-known technology stacks and official documentation sources.
- [REMOTE_CODE_EXECUTION]: No patterns involving the execution of untrusted remote code or scripts were identified. The described 'sync function' is a standard server-side JavaScript component of the Couchbase architecture managed by the developer on their own infrastructure.
- [DYNAMIC_EXECUTION]: The skill describes the use of SQL++ for local queries and JavaScript for sync functions. These are standard features of the Couchbase database engine and do not represent a security risk within the context of the skill's instructions.
- [OBFUSCATION]: The content is presented in clear, readable text. No hidden characters, Base64-encoded commands, or homoglyph-based deception techniques were found.
- [INDIRECT_PROMPT_INJECTION]: The skill provides templates for data handling and replication. While the applications built with these snippets will ingest data, the skill includes guidance on validation within sync functions to mitigate risks at the application layer.
Audit Metadata