isaaclab-preparing-assets-for-newton

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to process and convert external asset files (URDF, MJCF, USD), which constitutes an indirect prompt injection surface.
  • Ingestion points: External asset files such as URDF, MJCF, and USD payloads mentioned in SKILL.md and reference.md.
  • Boundary markers: The instructions do not specify any delimiters or safety warnings to ignore instructions embedded in the metadata or comments of these external assets.
  • Capability inventory: The skill provides commands in reference.md to execute Python scripts (scripts/environments/zero_agent.py) using the uv package manager, which interact with the simulation environment.
  • Sanitization: There is no mention of sanitizing or validating the contents of the imported asset files before processing them.
  • [COMMAND_EXECUTION]: The skill provides explicit shell commands in reference.md for validating asset migration and running smoke tests.
  • Evidence: uv run --extra isaacsim python scripts/environments/zero_agent.py --task TASK --num_envs 4 --viz none physics=physx
  • Context: These commands are used for legitimate testing and validation of the migrated assets within the Isaac Lab environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 09:37 PM
Security Audit — agent-trust-hub — isaaclab-preparing-assets-for-newton