isaac-sim-remote
Warn
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The
scripts/isaacsim_send.pyutility uses theeval()function to parse command-line arguments and performs dynamic code generation to wrap user scripts in isolated async function scopes. - [REMOTE_CODE_EXECUTION]: The skill's core purpose is to facilitate arbitrary Python code execution within the Isaac Sim environment via a TCP socket connection on port 8226.
- [DATA_EXFILTRATION]: The
scripts/console_log.pyscript accesses the application session log file from the local filesystem, which could lead to exposure of sensitive operational data or credentials if they are captured in logs. - [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface.
- Ingestion points: Simulation stage prim attributes (
scripts/stage_info.py) and application log files (scripts/console_log.py). - Boundary markers: Absent; external data is read and printed directly to the agent's context.
- Capability inventory: The agent can execute arbitrary Python code, modify the filesystem via simulation commands, and perform network operations via the simulator's Python environment.
- Sanitization: None; USD attribute values and log entries are processed as raw strings.
Audit Metadata