skills/getnao/nao/add-semantic-layer/Gen Agent Trust Hub

add-semantic-layer

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: Secret Management: The skill demonstrates good security posture by instructing the agent and user to store sensitive credentials like DBT_TOKEN and SNOWFLAKE_PASSWORD in environment variables instead of hardcoding them in configuration files.
  • [EXTERNAL_DOWNLOADS]: Tool Installation: The instructions include configuration for uvx to fetch and run dbt-mcp and mcp-server-snowflake. These are recognized tools for establishing database and metric connectivity in agentic workflows.
  • [COMMAND_EXECUTION]: Local Integration: The skill defines shell-based command execution for MCP servers to facilitate metric querying. These operations are limited to the scope of legitimate data analysis tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 09:39 AM