importing-kicad-projects

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands using the pcb utility (e.g., pcb import, pcb build, pcb apply). These commands are used to process hardware design files and modify the local repository state.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external KiCad project and schematic files, which could contain malicious instructions or metadata. The following evidence chain applies: 1. Ingestion points: The pcb import command reads .kicad_pro and .kicad_sch files from external paths provided to the agent. 2. Boundary markers: The instructions do not include explicit delimiters or safety warnings for the agent to disregard potential instructions embedded within the design files. 3. Capability inventory: The agent is authorized to execute shell commands and write files within the repository context. 4. Sanitization: No specific sanitization, validation, or filtering of the KiCad file content is described before the data is processed or interpreted.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:27 PM
Security Audit — agent-trust-hub — importing-kicad-projects