kicad-bom

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references external Model Context Protocol (MCP) endpoints (pcbparts.dev, api.zenode.ai) and a GitHub repository (i2cjak/American_Embedded_KiCad_Template) for component data and configuration templates. These resources are directly related to the skill's purpose of PCB part resolution and BOM management.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process KiCad project files and schematic value fields, which are external data sources.
  • Ingestion points: KiCad schematic files and component value fields (referenced in SKILL.md).
  • Boundary markers: None explicitly defined in the instructions.
  • Capability inventory: The agent is authorized to modify schematic symbols and their associated metadata fields (MPN, Manufacturer, LCSC number).
  • Sanitization: None explicitly defined. While this represents an attack surface common to file-processing tools, the skill provides specific guidance on field validation, which reduces the likelihood of accidental misconfiguration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 07:05 PM
Security Audit — agent-trust-hub — kicad-bom