isaaclab-installing-isaac-lab
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to execute shell commands extracted from local documentation for system installation, environment setup, and verification.
- [PRIVILEGE_ESCALATION]: The workflow explicitly includes the execution of commands using
sudofor installation steps that require administrative access, such as driver installation or system package updates. - [INDIRECT_PROMPT_INJECTION]: The skill treats the contents of
docs/source/setup/installation/index.rstin the local checkout as a trusted source of commands to be executed verbatim. This creates a vulnerability where data in the repository can influence the agent's actions. - Ingestion points: Documentation files located in the local checkout, specifically
docs/source/setup/installation/index.rstand its included fragments. - Boundary markers: Absent. The skill instructions command the agent to extract and execute steps verbatim without additional validation or boundary enforcement.
- Capability inventory: The skill has the capability to execute arbitrary shell commands, including those with elevated privileges via
sudo. - Sanitization: Absent. The skill explicitly forbids paraphrasing or substituting steps, which prevents the agent from filtering potentially malicious commands found in the documentation.
Audit Metadata