isaaclab-training-rl-agents

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of local Isaac Lab scripts and tools using uv run. This includes training scripts (isaaclab train), playback (isaaclab play), and maintenance tools (tools/skills/cli.py). These are standard operations within the Isaac Lab environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it interpolates user-supplied task names and configuration parameters into shell commands.
  • Ingestion points: User-provided inputs for task names and RL library selection as described in SKILL.md and evaluations.md.
  • Boundary markers: None identified; the skill does not instruct the agent to use specific delimiters or safety wrappers for user input.
  • Capability inventory: Execution of shell commands via the uv tool and Python argument list processing.
  • Sanitization: None identified; the instructions rely on the user providing valid registered task names (e.g., Isaac-Cartpole).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 09:37 PM
Security Audit — agent-trust-hub — isaaclab-training-rl-agents