isaac-sim-validator
Warn
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The shell script
scripts/validate_sim.shexecutes the user-provided script during its 'Level 3: Runtime Checks'. - Evidence: The script contains the command
timeout "$TIMEOUT" python3 "$SCRIPT" > "$RUNTIME_LOG" 2>&1which runs the input file directly on the host system. - [DATA_EXFILTRATION]: The skill implements defensive checks to prevent accidental data exposure or exfiltration.
- Evidence:
SKILL.mddefines rules to reject scripts containing hardcoded user paths (e.g.,/home/<user>/,C:\Users\<name>\) or bare IP addresses (e.g.,192.168.x.x). - [INDIRECT_PROMPT_INJECTION]: The skill has a vulnerability surface where it ingests and processes untrusted scripts and USD files.
- Ingestion points: The validation script
scripts/validate_sim.shtakes a script path as an argument. - Boundary markers: None present to distinguish between trusted and untrusted logic within the script.
- Capability inventory: The skill can execute Python scripts and read file contents via shell commands.
- Sanitization: It performs basic syntax checks and pattern matching (grep), but these do not prevent malicious logic within a syntactically valid script.
Audit Metadata