profile-isaac-sim

Warn

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's workflow for profiling extension unit tests directs the agent to capture a command line from the 'running process:' string in console logs and execute it directly in the shell. This dynamic command discovery and execution is a sensitive pattern that relies on the integrity of the log source.
  • [EXTERNAL_DOWNLOADS]: Fetches assets and configurations from an official Amazon S3 bucket used for NVIDIA Omniverse content staging to bypass interactive authentication during benchmarks.
  • [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection by ingesting and parsing untrusted data from external Tracy CSV exports and benchmark log files.
  • Ingestion points: Metric extraction from log files in SKILL.md and CSV data processing in scripts/compare_tracy_csvs.py.
  • Boundary markers: No explicit markers or delimiters are defined to separate the data from instructions during processing.
  • Capability inventory: The agent can execute several subprocess commands including python.sh, tracy-capture, and local scripts.
  • Sanitization: There is no evidence of input validation or content sanitization for the performance data being ingested.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 30, 2026, 03:04 PM
Security Audit — agent-trust-hub — profile-isaac-sim