couchbase-xdcr
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill provides the ability to retrieve and view document contents from database conflict logs through the
admin_xdcr_get_conflict_logtool. This creates a surface for indirect prompt injection where malicious content stored within database documents could potentially influence the agent's behavior during analysis. - Ingestion points: Document data is ingested into the agent's context via the
admin_xdcr_get_conflict_logtool (mentioned in SKILL.md and references/conflict-resolution.md). - Boundary markers: The instructions do not specify any boundary markers or instructions to treat the log content as untrusted data.
- Capability inventory: The skill possesses capabilities to modify cluster configurations, manage remote references, and update replication settings via
admin_xdcr_*tools. - Sanitization: No sanitization or validation steps are described for the data retrieved from the database logs before it is presented to the agent.
Audit Metadata