soc-security-skills
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The instructions are designed to facilitate structured hardware security analysis. No malicious patterns aimed at bypassing agent safety filters or manipulating model identity were found.- [DATA_EXFILTRATION]: All specialist skills include a 'Scope Constraints' section that explicitly prohibits network requests and access to sensitive directories such as home dotfiles. No data exfiltration vectors or hardcoded credentials were identified.- [EXTERNAL_DOWNLOADS]: The package uses the author's official GitHub repository for installation and updates. This behavior is consistent with standard vendor practices and does not include risky third-party downloads or piped remote execution.- [COMMAND_EXECUTION]: No dangerous shell commands or arbitrary execution patterns were found in the skill definitions. The provided pipeline scripts are local utilities for governance, linting, and budget tracking.- [INDIRECT_PROMPT_INJECTION]: While the skill processes untrusted input such as SoC descriptions, it implements a robust defense-in-depth strategy including mandatory 'Input Sanitization' steps to strip metacharacters and path traversal sequences, and uses structured 'DocumentEnvelopes' to maintain clear boundaries between system instructions and processed data.
Audit Metadata