isaac-sim-remote

Warn

Audited by Socket on Jul 30, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
scripts/isaacsim_send.py

No direct indicator of covert malware behavior (no persistence, hidden network destinations, or system-damaging logic) is present in this snippet. The primary security concern is that this is a high-abuse-risk remote code submission client: it transmits arbitrary Python code to a configurable server for execution and uses client-side `eval()` to interpret `--arg` values before embedding them into the payload. If included in a supply chain unexpectedly, it should be treated as a dangerous RCE transport component rather than benign automation.

Confidence: 72%Severity: 74%
AnomalyLOW
scripts/execute_command.py

No direct malicious payload indicators are present (no obfuscation, no network/file/credential operations in this fragment). However, the code is a generic, externally controlled command dispatcher: `command_name` and JSON-parsed `kwargs` are forwarded unvalidated into `omni.kit.commands.execute(...)`, and `undo_last` can trigger `omni.kit.commands.undo()`. In untrusted-input scenarios, this creates a meaningful risk of unintended/high-impact actions within the host OmniKit/Isaac environment, and it may also leak operational details via printed arguments/results.

Confidence: 66%Severity: 62%
Audit Metadata
Analyzed At
Jul 30, 2026, 03:05 PM
Package URL
pkg:socket/skills-sh/kaweees%2Fisaacsim-skill%2Fisaac-sim-remote%2F@cd38e155a1968ac19aa9dd5831c24ba3eb59710ac693d38ed600950e1dd04e27
Security Audit — socket — isaac-sim-remote