add-semantic-layer
Pass
Audited by Gen Agent Trust Hub on Apr 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [SAFE]: Secret Management: The skill demonstrates good security posture by instructing the agent and user to store sensitive credentials like DBT_TOKEN and SNOWFLAKE_PASSWORD in environment variables instead of hardcoding them in configuration files.
- [EXTERNAL_DOWNLOADS]: Tool Installation: The instructions include configuration for uvx to fetch and run dbt-mcp and mcp-server-snowflake. These are recognized tools for establishing database and metric connectivity in agentic workflows.
- [COMMAND_EXECUTION]: Local Integration: The skill defines shell-based command execution for MCP servers to facilitate metric querying. These operations are limited to the scope of legitimate data analysis tasks.
Audit Metadata