autodesk-bim-360

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the user to install the @membranehq/cli package from the NPM registry, which is the official command-line interface for the Membrane platform.\n- [COMMAND_EXECUTION]: The skill relies on the execution of shell commands through the membrane utility to manage project connections, poll for connection status, and execute API actions.\n- [INDIRECT_PROMPT_INJECTION]: The skill interacts with the Autodesk BIM 360 API, which acts as an ingestion point for external, untrusted data that could influence agent behavior.\n
  • Ingestion points: The agent retrieves and processes project data and issue records from Autodesk BIM 360 using membrane action run and membrane request commands as described in SKILL.md.\n
  • Boundary markers: There are no specified delimiters or instructions to the agent to disregard instructions potentially embedded within the BIM 360 data.\n
  • Capability inventory: The skill allows the agent to execute CLI commands and perform authenticated network requests via the Membrane platform.\n
  • Sanitization: No procedures for sanitizing or validating API responses from Autodesk BIM 360 are outlined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:38 PM
Security Audit — agent-trust-hub — autodesk-bim-360