configuring-dbt-mcp-server

Pass

Audited by Gen Agent Trust Hub on Mar 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security vulnerabilities or malicious patterns were identified in the skill files.
  • [EXTERNAL_DOWNLOADS]: The skill references the dbt-mcp package to be run via uvx. These are official tools from the author (dbt-labs) and Astral, respectively, and are used for their intended configuration purpose.
  • [CREDENTIALS_UNSAFE]: While the skill manages sensitive configuration (tokens and account IDs), it provides clear security warnings and instructions on using environment variables and .env files with .gitignore to prevent credential leakage.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 13, 2026, 03:23 PM