easyeda-schematic-net-fanout
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use
subprocess.runto executecurlcommands. These operations are directed athttp://localhost:49620, the default port for the vendor's local API gateway. The guidance includes security best practices, such as writing payloads to temporary files usingtempfileandos.path.jointo prevent command injection via shell escaping. - [EXTERNAL_DOWNLOADS]: The skill links to official and established extensions and repositories within the EasyEDA ecosystem, including
easyeda/easyeda-api-skillon GitHub and therun-api-gatewayplugin onjlc-ext.com. These are verified vendor-owned resources. - [SAFE]: The skill's dynamic code generation and execution are confined to controlling the local CAD environment via a documented bridge. Analysis of the metadata, documentation, and logic found no evidence of prompt injection, credential harvesting, or unauthorized network activity.
Audit Metadata