isaac-sim-robot-navigation

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to interact with and process external data sources, specifically USD (Universal Scene Description) stages and occupancy map files (e.g., map.yaml). This presents a vulnerability surface for indirect prompt injection, where an attacker could embed malicious instructions in these data files to influence the agent's simulation setup or execution.
  • Ingestion points: Loading USD stages and processing occupancy map configuration files.
  • Boundary markers: The skill does not provide specific delimiters or warnings to ignore instructions embedded within the asset files.
  • Capability inventory: The skill utilizes the Isaac Sim API to control physics, modify scene primitives (stripping Physics APIs), and manage simulation timelines.
  • Sanitization: There are no instructions for validating or sanitizing the content of the external USD or YAML files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 03:04 PM
Security Audit — agent-trust-hub — isaac-sim-robot-navigation