autodesk-bim-360
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the user to install the
@membranehq/clipackage from the NPM registry, which is the official command-line interface for the Membrane platform.\n- [COMMAND_EXECUTION]: The skill relies on the execution of shell commands through themembraneutility to manage project connections, poll for connection status, and execute API actions.\n- [INDIRECT_PROMPT_INJECTION]: The skill interacts with the Autodesk BIM 360 API, which acts as an ingestion point for external, untrusted data that could influence agent behavior.\n - Ingestion points: The agent retrieves and processes project data and issue records from Autodesk BIM 360 using
membrane action runandmembrane requestcommands as described in SKILL.md.\n - Boundary markers: There are no specified delimiters or instructions to the agent to disregard instructions potentially embedded within the BIM 360 data.\n
- Capability inventory: The skill allows the agent to execute CLI commands and perform authenticated network requests via the Membrane platform.\n
- Sanitization: No procedures for sanitizing or validating API responses from Autodesk BIM 360 are outlined in the instructions.
Audit Metadata