microduck-skill
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple shell scripts (
doctor.sh,smoke.sh,train.sh,export_publish.sh) and usesuv runto execute Python code. These operations are within the scope of its defined purpose for managing reinforcement learning pipelines. - [PRIVILEGE_ESCALATION]: The deployment documentation in
references/DEPLOY.mdand theexport_publish.shscript suggest runningsudo robotctlcommands. The instructions correctly stipulate that these should be printed for the user and only executed if the user explicitly requests installation on hardware they own. - [EXTERNAL_DOWNLOADS]: The
scripts/doctor.shscript performs agit clonefromhttps://github.com/pollen-robotics/microduck_rl. As this is a well-known repository related to the skill's primary function and the skill was developed by a known entity, this is considered a functional requirement. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as reward configurations, task IDs, and Hugging Face repository descriptions. While it includes validation via
scripts/gate_check.pyfor model shapes, it lacks explicit sanitization or boundary markers for textual metadata (e.g., repository descriptions or custom task configurations) that could influence the agent's context during the training or publishing phases.
Audit Metadata