houdini

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external 3D data, including Houdini scene files (.hip, .usd), simulation logs, and viewport screenshots. Maliciously crafted geometry attributes, metadata, or logs could be used to attempt to influence the agent's behavior during analysis.
  • Ingestion points: Loading .hip files in SKILL.md, processing USD Scene Graph data in gemini.md, and analyzing viewport screenshots in gemini.md.
  • Boundary markers: There are no explicit instructions or delimiters provided to differentiate untrusted scene data from the agent's primary directives.
  • Capability inventory: The skill provides scripts that perform file system writes (creating .hda files in gpt.md) and utilize local interpreters (hython, hbatch) for simulation cooking and rendering.
  • Sanitization: No sanitization or validation logic is defined for the attributes or metadata extracted from Houdini files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 12:40 PM
Security Audit — agent-trust-hub — houdini