soc-pipeline

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface.
  • Ingestion points: The agent is instructed to read pipeline_state.json and multiple rule files located at ../../rules/ (SKILL.md).
  • Boundary markers: No explicit delimiters or instructions to disregard embedded commands are provided.
  • Capability inventory: The agent can execute update_state.py and call specialized MCP tools (soc-build.soc_sim, soc-build.soc_syn, soc-openroad.*).
  • Sanitization: There is no mention of input validation or content sanitization for ingested data.
  • [COMMAND_EXECUTION]: The skill workflow requires the execution of local scripts and MCP-registered tools. Evidence includes instructions to run update_state.py and use tools for simulation, synthesis, and physical design handoff (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 04:53 PM
Security Audit — agent-trust-hub — soc-pipeline