isaac-sim-validator

Warn

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The shell script scripts/validate_sim.sh executes the user-provided script during its 'Level 3: Runtime Checks'.
  • Evidence: The script contains the command timeout "$TIMEOUT" python3 "$SCRIPT" > "$RUNTIME_LOG" 2>&1 which runs the input file directly on the host system.
  • [DATA_EXFILTRATION]: The skill implements defensive checks to prevent accidental data exposure or exfiltration.
  • Evidence: SKILL.md defines rules to reject scripts containing hardcoded user paths (e.g., /home/<user>/, C:\Users\<name>\) or bare IP addresses (e.g., 192.168.x.x).
  • [INDIRECT_PROMPT_INJECTION]: The skill has a vulnerability surface where it ingests and processes untrusted scripts and USD files.
  • Ingestion points: The validation script scripts/validate_sim.sh takes a script path as an argument.
  • Boundary markers: None present to distinguish between trusted and untrusted logic within the script.
  • Capability inventory: The skill can execute Python scripts and read file contents via shell commands.
  • Sanitization: It performs basic syntax checks and pattern matching (grep), but these do not prevent malicious logic within a syntactically valid script.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 30, 2026, 03:04 PM
Security Audit — agent-trust-hub — isaac-sim-validator