autodesk-revit
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package from the public NPM registry. This is the official tool provided by the skill's author (membranedev) to interact with their platform.
- [COMMAND_EXECUTION]: Provides instructions to execute shell commands via the membrane CLI for logging in, creating connections, and running Revit-related actions.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and manage Revit data, including element parameters and model views. This creates a surface where the agent could ingest untrusted third-party content (e.g., text within a BIM project) that might contain malicious instructions. 1. Ingestion points: Data entering via 'membrane action run' and 'membrane request' (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Subprocess calls via CLI (SKILL.md). 4. Sanitization: Absent.
- [SAFE]: Authentication is handled through a secure browser-based OAuth flow facilitated by the Membrane platform, ensuring that no sensitive credentials or API keys are hardcoded or stored insecurely within the skill environment.
Audit Metadata