omni-to-dbt-metricflow
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes several standard command-line utilities including
omni,dbt,mf(MetricFlow CLI),rg(ripgrep), andtailto manage model definitions, validate YAML syntax, and perform warehouse parity checks. - [EXTERNAL_DOWNLOADS]: The instructions recommend installing the
dbt-metricflowpackage viapipif the tool is not present in the user's environment. This is a standard dependency for the skill's primary purpose. - [DYNAMIC_CONTEXT_INJECTION]: The skill references the
!command syntax (e.g.,! omni config login <profile>) to facilitate user authentication when the agent detects an unauthorized state. - [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface where untrusted data is fetched from the Omni API (
omni models yaml-get). It includes a mandatory safety instruction (marked with a lock icon) for the agent to treat this data as translation input only and to stop and notify the user if the data attempts to issue commands or bypass the workflow.
Audit Metadata