snowflake

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the @membranehq/cli package from the official NPM registry to facilitate communication with the Snowflake integration service.
  • [COMMAND_EXECUTION]: The skill utilizes local shell commands (membrane login, membrane connection, membrane action, membrane request) to manage authentication, discover available Snowflake actions, and execute data operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes structured and unstructured data returned from the Snowflake API, which represents a potential surface for indirect prompt injection if the stored data contains malicious instructions intended for the agent.
  • Ingestion points: Data retrieved from Snowflake via membrane action run and membrane request (SKILL.md).
  • Boundary markers: None explicitly defined in the skill instructions to delimit external data from agent commands.
  • Capability inventory: The agent can execute system commands through the Membrane CLI and perform network requests via the Membrane proxy (SKILL.md).
  • Sanitization: The skill relies on the underlying agent's default safety guardrails and Membrane's server-side schema validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:51 PM
Security Audit — agent-trust-hub — snowflake