eda-vm
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides templates and protocols for executing arbitrary shell commands and scripts on a remote Linux host (
vm) via SSH. - [DATA_EXFILTRATION]: Instructions include the bidirectional transfer of local project files and remote tool outputs using the SCP protocol, identifying the specific requirement for the
-Oflag for legacy compatibility. - [INDIRECT_PROMPT_INJECTION]: As the skill is designed to ingest and process external project source code (Verilog, SystemVerilog) and simulation logs from third-party tools, it presents an attack surface for indirect prompt injection if those files contain malicious instructions.
Audit Metadata