cli-anything-freecad
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The installation instructions include running
pip install -e freecad/agent-harness, which executes an editable installation of a local Python package from a relative directory. - [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from untrusted sources, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: The skill uses
import,mesh import, andspreadsheet import-materialto load external CAD, mesh, and configuration files into the agent's context (documented in SKILL.md). - Boundary markers: There are no defined delimiters or instructions provided to the agent to ignore potentially malicious instructions embedded within the imported CAD or mesh files.
- Capability inventory: The skill has extensive capabilities including 3D model manipulation, G-code generation for CNC machining (
cam generate-gcode), and file system writes via various export commands across the harness scripts. - Sanitization: The skill lacks mechanisms to sanitize or validate the content of the imported files before they are processed by the agent's geometric reasoning or execution loops.
Audit Metadata