autodesk-revit

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package from the public NPM registry. This is the official tool provided by the skill's author (membranedev) to interact with their platform.
  • [COMMAND_EXECUTION]: Provides instructions to execute shell commands via the membrane CLI for logging in, creating connections, and running Revit-related actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and manage Revit data, including element parameters and model views. This creates a surface where the agent could ingest untrusted third-party content (e.g., text within a BIM project) that might contain malicious instructions. 1. Ingestion points: Data entering via 'membrane action run' and 'membrane request' (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Subprocess calls via CLI (SKILL.md). 4. Sanitization: Absent.
  • [SAFE]: Authentication is handled through a secure browser-based OAuth flow facilitated by the Membrane platform, ensuring that no sensitive credentials or API keys are hardcoded or stored insecurely within the skill environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:38 PM
Security Audit — agent-trust-hub — autodesk-revit