cad-viewer

Warn

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the cadgen utility, such as cadgen viewer, cadgen viewer list, and cadgen viewer stop to manage the lifecycle of the visualization server.
  • [PRIVILEGE_ESCALATION]: The instructions in SKILL.md explicitly suggest that the agent should "rerun with the needed permission/escalation" if it encounters EPERM or EACCES errors when attempting to bind to a local port. This encourages the agent to seek higher privileges to bypass environment restrictions.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it is designed to ingest and process various external CAD and robot-description file formats (such as .step, .urdf, .sdf, .dxf) which could contain malicious metadata or instructions intended to influence the agent.
  • Ingestion points: External model and description files loaded from the local filesystem for visualization.
  • Boundary markers: No explicit boundary markers or "ignore instructions" warnings are provided for the content of processed files.
  • Capability inventory: Shell command execution via cadgen and directory traversal via cd commands.
  • Sanitization: The skill does not describe specific sanitization or validation logic for the content of the files before they are processed by the viewer.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 29, 2026, 01:29 PM
Security Audit — agent-trust-hub — cad-viewer