fluidsim
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides tools to ingest and process external data, such as HDF5 datasets and JSON configuration files. This data ingestion is heavily guarded by the validation logic in
scripts/_common.pyandscripts/_schema.py, which enforce strict type checking, value bounds, and path safety (explicitly rejecting symlinks, parent traversal, and URI schemes). - [DYNAMIC_EXECUTION]: The
scripts/simulation_dry_run.pyutility generates a Python simulation script based on a validated configuration. This is a core functional requirement and is implemented securely using a static template and a hardcoded allowlist for solver modules. The generated script also incorporates a safety gate, requiring an explicit user acknowledgment and an execution flag to run. - [COMMAND_EXECUTION]: The skill documentation warns against using dangerous features of external CLIs, such as
fluidsim-restart --modify-params, which can execute arbitrary Python strings. The skill's own generated tools do not use these vulnerable patterns, ensuring that simulation management remains within safe operational bounds.
Audit Metadata