fluidsim

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides tools to ingest and process external data, such as HDF5 datasets and JSON configuration files. This data ingestion is heavily guarded by the validation logic in scripts/_common.py and scripts/_schema.py, which enforce strict type checking, value bounds, and path safety (explicitly rejecting symlinks, parent traversal, and URI schemes).
  • [DYNAMIC_EXECUTION]: The scripts/simulation_dry_run.py utility generates a Python simulation script based on a validated configuration. This is a core functional requirement and is implemented securely using a static template and a hardcoded allowlist for solver modules. The generated script also incorporates a safety gate, requiring an explicit user acknowledgment and an execution flag to run.
  • [COMMAND_EXECUTION]: The skill documentation warns against using dangerous features of external CLIs, such as fluidsim-restart --modify-params, which can execute arbitrary Python strings. The skill's own generated tools do not use these vulnerable patterns, ensuring that simulation management remains within safe operational bounds.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — fluidsim