dbt-analytics-engineering

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is authored by dbt-labs, a trusted organization, and is hosted in an official, trusted repository.
  • [SAFE]: The skill includes comprehensive security instructions (in the 'Handling external data' section of SKILL.md and 'Managing dbt Packages' reference) that explicitly warn the agent against executing instructions embedded in data or API responses. This mitigates risks associated with indirect prompt injection.
  • [SAFE]: Command execution is limited to standard dbt and jq tools within the allowed-tools configuration, which is appropriate for the skill's primary purpose.
  • [SAFE]: Package management and data exploration use official dbt tools and registries (hub.getdbt.com) and include security notes requiring user confirmation for installations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 05:50 PM
Security Audit — agent-trust-hub — dbt-analytics-engineering