soc-security-skills

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The instructions are designed to facilitate structured hardware security analysis. No malicious patterns aimed at bypassing agent safety filters or manipulating model identity were found.- [DATA_EXFILTRATION]: All specialist skills include a 'Scope Constraints' section that explicitly prohibits network requests and access to sensitive directories such as home dotfiles. No data exfiltration vectors or hardcoded credentials were identified.- [EXTERNAL_DOWNLOADS]: The package uses the author's official GitHub repository for installation and updates. This behavior is consistent with standard vendor practices and does not include risky third-party downloads or piped remote execution.- [COMMAND_EXECUTION]: No dangerous shell commands or arbitrary execution patterns were found in the skill definitions. The provided pipeline scripts are local utilities for governance, linting, and budget tracking.- [INDIRECT_PROMPT_INJECTION]: While the skill processes untrusted input such as SoC descriptions, it implements a robust defense-in-depth strategy including mandatory 'Input Sanitization' steps to strip metacharacters and path traversal sequences, and uses structured 'DocumentEnvelopes' to maintain clear boundaries between system instructions and processed data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 08:49 PM