isaac-sim-orchestrator
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The debug protocol instructs the agent to execute shell commands for process management (
pkill -f "kit/kit") and cache cleanup (removing files in/dev/shm/carb-*). - [REMOTE_CODE_EXECUTION]: The skill's primary workflow involves generating Python scripts and executing them using the simulation's shell wrapper (
isaac-sim.sh --exec script.py), representing dynamic code execution. - [PROMPT_INJECTION]: The skill processes natural-language requests to decompose tasks and generate executable simulation code, which constitutes a surface for indirect prompt injection.
- Ingestion points: Natural-language requests for simulation scenes, robot control, and data collection (SKILL.md).
- Boundary markers: Absent; the skill does not define delimiters or provide instructions to ignore embedded commands within user requests.
- Capability inventory: File writing, shell command execution (
pkill), and Python script execution viaisaac-sim.sh. - Sanitization: No sanitization, validation, or escaping of the natural-language input is specified before it is processed by the agent.
Audit Metadata