easyeda-schematic-net-fanout

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use subprocess.run to execute curl commands. These operations are directed at http://localhost:49620, the default port for the vendor's local API gateway. The guidance includes security best practices, such as writing payloads to temporary files using tempfile and os.path.join to prevent command injection via shell escaping.
  • [EXTERNAL_DOWNLOADS]: The skill links to official and established extensions and repositories within the EasyEDA ecosystem, including easyeda/easyeda-api-skill on GitHub and the run-api-gateway plugin on jlc-ext.com. These are verified vendor-owned resources.
  • [SAFE]: The skill's dynamic code generation and execution are confined to controlling the local CAD environment via a documented bridge. Analysis of the metadata, documentation, and logic found no evidence of prompt injection, credential harvesting, or unauthorized network activity.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 12:03 PM
Security Audit — agent-trust-hub — easyeda-schematic-net-fanout