cli-anything-freecad

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The installation instructions include running pip install -e freecad/agent-harness, which executes an editable installation of a local Python package from a relative directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from untrusted sources, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: The skill uses import, mesh import, and spreadsheet import-material to load external CAD, mesh, and configuration files into the agent's context (documented in SKILL.md).
  • Boundary markers: There are no defined delimiters or instructions provided to the agent to ignore potentially malicious instructions embedded within the imported CAD or mesh files.
  • Capability inventory: The skill has extensive capabilities including 3D model manipulation, G-code generation for CNC machining (cam generate-gcode), and file system writes via various export commands across the harness scripts.
  • Sanitization: The skill lacks mechanisms to sanitize or validate the content of the imported files before they are processed by the agent's geometric reasoning or execution loops.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:21 PM
Security Audit — agent-trust-hub — cli-anything-freecad