couchbase-sqlpp-tuning

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: References the celticht32/MCP-Couchbase repository for cluster interaction. This is a vendor-owned resource essential for the skill's functionality and is documented neutrally.
  • [DATA_EXFILTRATION]: Utilizes tools that read system catalogs (system:completed_requests) and sample document data (cb_get_schema_for_collection). These operations are necessary for query performance diagnosis and schema discovery.
  • [COMMAND_EXECUTION]: Provides instructions for environment setup, including running the MCP server with uv run and configuring read-only modes via environment variables.
  • [PROMPT_INJECTION]: The skill processes untrusted user input in the form of SQL queries and EXPLAIN plans, creating an inherent surface for indirect prompt injection.
  • Ingestion points: User-provided SQL statements and tool outputs from cb_explain_query (SKILL.md, references/diagnostic-workflow.md).
  • Boundary markers: Absent; the agent is instructed to process the query text directly.
  • Capability inventory: Index creation (admin_index_create), cluster queries (cb_query), and local server execution (uv run) (references/diagnostic-workflow.md).
  • Sanitization: Not explicitly defined for the agent's context; the documentation focuses on preventing traditional SQL injection rather than prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 02:52 AM
Security Audit — agent-trust-hub — couchbase-sqlpp-tuning