isaaclab-diagnosing-joint-poses
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The validation section provides a command to run a local CLI tool (
tools/skills/cli.py) usinguv. This is a standard development practice for verifying skill configuration and does not involve remote code execution or suspicious parameters. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process natural language instructions regarding robot poses (e.g., "gripper fingers down"). This creates an indirect prompt injection surface; however, the workflow explicitly requires the agent to validate requests against measurable simulation state and joint limits, which serves as a functional safeguard against malicious or physically impossible instructions.
- [DATA_EXPOSURE]: The skill references local configuration files and scripts within the Isaac Lab directory structure (
source/isaaclab/...). These are standard project references necessary for the skill's functionality and do not involve sensitive credential paths or unauthorized data exfiltration.
Audit Metadata