cloudbase-document-database-web-sdk

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external NoSQL collections, creating a surface for indirect prompt injection.
  • Ingestion points: Data entry occurs via db.collection().get(), .watch(), and .aggregate() as documented in complex-queries.md, realtime.md, and aggregation.md.
  • Boundary markers: There are no explicit instructions or delimiters defined to separate retrieved data from agent instructions, increasing the risk of the agent obeying instructions embedded in the data.
  • Capability inventory: The skill provides powerful database write capabilities including .add() and .update() in crud-operations.md, and the ability to modify access control lists through the managePermissions() tool as described in security-rules.md.
  • Sanitization: Although crud-operations.md includes an example of a validateTodo function, there is no enforced or recommended escaping or sanitization of external content prior to processing by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — cloudbase-document-database-web-sdk