dbt-cloud
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing the
@membranehq/clitool from the NPM registry, which is a trusted and well-known service provider associated with the skill's author. - [COMMAND_EXECUTION]: The skill instructs the agent to use shell commands through the
membraneCLI. These commands are intended for legitimate Dbt Cloud API interactions and environment management. - [INDIRECT_PROMPT_INJECTION]: The skill interacts with the Dbt Cloud API, which represents an external data ingestion surface.
- Ingestion points: Dbt Cloud API responses retrieved via the
membraneCLI in SKILL.md. - Boundary markers: Not present.
- Capability inventory: Shell command execution via the
membraneCLI throughout SKILL.md. - Sanitization: The skill relies on the Membrane platform's pre-built action schemas and does not include explicit prompt-level sanitization for external data.
Audit Metadata