isaaclab-installing-isaac-lab

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to execute shell commands extracted from local documentation for system installation, environment setup, and verification.
  • [PRIVILEGE_ESCALATION]: The workflow explicitly includes the execution of commands using sudo for installation steps that require administrative access, such as driver installation or system package updates.
  • [INDIRECT_PROMPT_INJECTION]: The skill treats the contents of docs/source/setup/installation/index.rst in the local checkout as a trusted source of commands to be executed verbatim. This creates a vulnerability where data in the repository can influence the agent's actions.
  • Ingestion points: Documentation files located in the local checkout, specifically docs/source/setup/installation/index.rst and its included fragments.
  • Boundary markers: Absent. The skill instructions command the agent to extract and execute steps verbatim without additional validation or boundary enforcement.
  • Capability inventory: The skill has the capability to execute arbitrary shell commands, including those with elevated privileges via sudo.
  • Sanitization: Absent. The skill explicitly forbids paraphrasing or substituting steps, which prevents the agent from filtering potentially malicious commands found in the documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 09:37 PM
Security Audit — agent-trust-hub — isaaclab-installing-isaac-lab