cad-viewer
Warn
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the
cadgenutility, such ascadgen viewer,cadgen viewer list, andcadgen viewer stopto manage the lifecycle of the visualization server. - [PRIVILEGE_ESCALATION]: The instructions in
SKILL.mdexplicitly suggest that the agent should "rerun with the needed permission/escalation" if it encountersEPERMorEACCESerrors when attempting to bind to a local port. This encourages the agent to seek higher privileges to bypass environment restrictions. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it is designed to ingest and process various external CAD and robot-description file formats (such as
.step,.urdf,.sdf,.dxf) which could contain malicious metadata or instructions intended to influence the agent. - Ingestion points: External model and description files loaded from the local filesystem for visualization.
- Boundary markers: No explicit boundary markers or "ignore instructions" warnings are provided for the content of processed files.
- Capability inventory: Shell command execution via
cadgenand directory traversal viacdcommands. - Sanitization: The skill does not describe specific sanitization or validation logic for the content of the files before they are processed by the viewer.
Audit Metadata