teamcity

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions rely on the membrane CLI to manage authentication, connection lifecycle, and action execution. Commands like membrane login, membrane connection ensure, and membrane action run are used to interact with the environment and the TeamCity API.\n- [EXTERNAL_DOWNLOADS]: The skill directs the user to install the @membranehq/cli package from the official NPM registry, which is the vendor's primary interface for managing integrations.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes build configurations and logs from TeamCity, which introduces a potential surface for indirect prompt injection from untrusted development data.\n
  • Ingestion points: Data enters the agent context through the outputs of membrane action run and membrane request.\n
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are used when presenting TeamCity data to the agent.\n
  • Capability inventory: The skill allows network requests to the TeamCity API and execution of pre-defined integration actions.\n
  • Sanitization: No specific filtering or sanitization of external build data is documented in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:19 AM
Security Audit — agent-trust-hub — teamcity