isaac-sim-orchestrator

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The debug protocol instructs the agent to execute shell commands for process management (pkill -f "kit/kit") and cache cleanup (removing files in /dev/shm/carb-*).
  • [REMOTE_CODE_EXECUTION]: The skill's primary workflow involves generating Python scripts and executing them using the simulation's shell wrapper (isaac-sim.sh --exec script.py), representing dynamic code execution.
  • [PROMPT_INJECTION]: The skill processes natural-language requests to decompose tasks and generate executable simulation code, which constitutes a surface for indirect prompt injection.
  • Ingestion points: Natural-language requests for simulation scenes, robot control, and data collection (SKILL.md).
  • Boundary markers: Absent; the skill does not define delimiters or provide instructions to ignore embedded commands within user requests.
  • Capability inventory: File writing, shell command execution (pkill), and Python script execution via isaac-sim.sh.
  • Sanitization: No sanitization, validation, or escaping of the natural-language input is specified before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 03:04 PM
Security Audit — agent-trust-hub — isaac-sim-orchestrator