isaac-sim-remote
Audited by Socket on Jul 30, 2026
2 alerts found:
SecurityAnomalyNo direct indicator of covert malware behavior (no persistence, hidden network destinations, or system-damaging logic) is present in this snippet. The primary security concern is that this is a high-abuse-risk remote code submission client: it transmits arbitrary Python code to a configurable server for execution and uses client-side `eval()` to interpret `--arg` values before embedding them into the payload. If included in a supply chain unexpectedly, it should be treated as a dangerous RCE transport component rather than benign automation.
No direct malicious payload indicators are present (no obfuscation, no network/file/credential operations in this fragment). However, the code is a generic, externally controlled command dispatcher: `command_name` and JSON-parsed `kwargs` are forwarded unvalidated into `omni.kit.commands.execute(...)`, and `undo_last` can trigger `omni.kit.commands.undo()`. In untrusted-input scenarios, this creates a meaningful risk of unintended/high-impact actions within the host OmniKit/Isaac environment, and it may also leak operational details via printed arguments/results.