teamcity
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions rely on the
membraneCLI to manage authentication, connection lifecycle, and action execution. Commands likemembrane login,membrane connection ensure, andmembrane action runare used to interact with the environment and the TeamCity API.\n- [EXTERNAL_DOWNLOADS]: The skill directs the user to install the@membranehq/clipackage from the official NPM registry, which is the vendor's primary interface for managing integrations.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes build configurations and logs from TeamCity, which introduces a potential surface for indirect prompt injection from untrusted development data.\n - Ingestion points: Data enters the agent context through the outputs of
membrane action runandmembrane request.\n - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are used when presenting TeamCity data to the agent.\n
- Capability inventory: The skill allows network requests to the TeamCity API and execution of pre-defined integration actions.\n
- Sanitization: No specific filtering or sanitization of external build data is documented in the skill instructions.
Audit Metadata