isaac-sim-remote

Warn

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The scripts/isaacsim_send.py utility uses the eval() function to parse command-line arguments and performs dynamic code generation to wrap user scripts in isolated async function scopes.
  • [REMOTE_CODE_EXECUTION]: The skill's core purpose is to facilitate arbitrary Python code execution within the Isaac Sim environment via a TCP socket connection on port 8226.
  • [DATA_EXFILTRATION]: The scripts/console_log.py script accesses the application session log file from the local filesystem, which could lead to exposure of sensitive operational data or credentials if they are captured in logs.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface.
  • Ingestion points: Simulation stage prim attributes (scripts/stage_info.py) and application log files (scripts/console_log.py).
  • Boundary markers: Absent; external data is read and printed directly to the agent's context.
  • Capability inventory: The agent can execute arbitrary Python code, modify the filesystem via simulation commands, and perform network operations via the simulator's Python environment.
  • Sanitization: None; USD attribute values and log entries are processed as raw strings.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 30, 2026, 03:04 PM
Security Audit — agent-trust-hub — isaac-sim-remote