registry-search
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, specifically registry search results and board source code, which creates a surface for indirect prompt injection.
- Ingestion points: Data enters the agent context via
pcb searchresults,pcb docoutput, and content fromgit cloneoperations (SKILL.md). - Boundary markers: The instructions do not specify the use of delimiters or warning markers for the ingested content.
- Capability inventory: The skill has access to shell commands (
pcb,git,diode_list_boards) and can perform network operations (SKILL.md). - Sanitization: There is no mention of sanitizing or escaping the external content before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill interacts with external resources to fetch information and source code.
- Registry access: Fetches documentation and package data from the vendor's registry at
code.diode.computerusing thepcb doccommand. - Git cloning: Clones external repositories via HTTPS for board inspection, though it specifies doing so outside the current checkout for safety.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute several CLI tools to perform its primary functions.
- Tool usage: Utilizes
pcb search,pcb doc,git clone, anddiode_list_boardsto interact with the filesystem and network.
Audit Metadata