isaac-sim-robot-navigation
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to interact with and process external data sources, specifically USD (Universal Scene Description) stages and occupancy map files (e.g., map.yaml). This presents a vulnerability surface for indirect prompt injection, where an attacker could embed malicious instructions in these data files to influence the agent's simulation setup or execution.
- Ingestion points: Loading USD stages and processing occupancy map configuration files.
- Boundary markers: The skill does not provide specific delimiters or warnings to ignore instructions embedded within the asset files.
- Capability inventory: The skill utilizes the Isaac Sim API to control physics, modify scene primitives (stripping Physics APIs), and manage simulation timelines.
- Sanitization: There are no instructions for validating or sanitizing the content of the external USD or YAML files before processing.
Audit Metadata