couchbase-xdcr

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill provides the ability to retrieve and view document contents from database conflict logs through the admin_xdcr_get_conflict_log tool. This creates a surface for indirect prompt injection where malicious content stored within database documents could potentially influence the agent's behavior during analysis.
  • Ingestion points: Document data is ingested into the agent's context via the admin_xdcr_get_conflict_log tool (mentioned in SKILL.md and references/conflict-resolution.md).
  • Boundary markers: The instructions do not specify any boundary markers or instructions to treat the log content as untrusted data.
  • Capability inventory: The skill possesses capabilities to modify cluster configurations, manage remote references, and update replication settings via admin_xdcr_* tools.
  • Sanitization: No sanitization or validation steps are described for the data retrieved from the database logs before it is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 02:52 AM
Security Audit — agent-trust-hub — couchbase-xdcr