couchbase-sqlpp-tuning
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: References the
celticht32/MCP-Couchbaserepository for cluster interaction. This is a vendor-owned resource essential for the skill's functionality and is documented neutrally. - [DATA_EXFILTRATION]: Utilizes tools that read system catalogs (
system:completed_requests) and sample document data (cb_get_schema_for_collection). These operations are necessary for query performance diagnosis and schema discovery. - [COMMAND_EXECUTION]: Provides instructions for environment setup, including running the MCP server with
uv runand configuring read-only modes via environment variables. - [PROMPT_INJECTION]: The skill processes untrusted user input in the form of SQL queries and EXPLAIN plans, creating an inherent surface for indirect prompt injection.
- Ingestion points: User-provided SQL statements and tool outputs from
cb_explain_query(SKILL.md, references/diagnostic-workflow.md). - Boundary markers: Absent; the agent is instructed to process the query text directly.
- Capability inventory: Index creation (
admin_index_create), cluster queries (cb_query), and local server execution (uv run) (references/diagnostic-workflow.md). - Sanitization: Not explicitly defined for the agent's context; the documentation focuses on preventing traditional SQL injection rather than prompt injection.
Audit Metadata