importing-kicad-projects
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands using the
pcbutility (e.g.,pcb import,pcb build,pcb apply). These commands are used to process hardware design files and modify the local repository state. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external KiCad project and schematic files, which could contain malicious instructions or metadata. The following evidence chain applies: 1. Ingestion points: The
pcb importcommand reads.kicad_proand.kicad_schfiles from external paths provided to the agent. 2. Boundary markers: The instructions do not include explicit delimiters or safety warnings for the agent to disregard potential instructions embedded within the design files. 3. Capability inventory: The agent is authorized to execute shell commands and write files within the repository context. 4. Sanitization: No specific sanitization, validation, or filtering of the KiCad file content is described before the data is processed or interpreted.
Audit Metadata