soc-pipeline
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface.
- Ingestion points: The agent is instructed to read pipeline_state.json and multiple rule files located at ../../rules/ (SKILL.md).
- Boundary markers: No explicit delimiters or instructions to disregard embedded commands are provided.
- Capability inventory: The agent can execute update_state.py and call specialized MCP tools (soc-build.soc_sim, soc-build.soc_syn, soc-openroad.*).
- Sanitization: There is no mention of input validation or content sanitization for ingested data.
- [COMMAND_EXECUTION]: The skill workflow requires the execution of local scripts and MCP-registered tools. Evidence includes instructions to run update_state.py and use tools for simulation, synthesis, and physical design handoff (SKILL.md).
Audit Metadata