physicsnemo-discover

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches the official PhysicsNeMo source code from NVIDIA's GitHub repository to enable live discovery of project artifacts and documentation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data by reading files such as READMEs, docstrings, and package initialization files from the target repository, which serves as a potential surface for indirect instructions.
  • Ingestion points: Read operations on examples/**/README.md, physicsnemo/**/*.py, and docs/*.rst within the cloned or local repository.
  • Boundary markers: Instructions explicitly require the agent to flag content from experimental/ directories as unstable.
  • Capability inventory: Access to Read, Glob, Grep, Bash, and git tools for repository interaction.
  • Sanitization: The skill emphasizes path verification using ls -d but does not define content-level sanitization for the retrieved documentation.
  • [COMMAND_EXECUTION]: The skill utilizes shell utilities including git clone for repository acquisition, as well as ls, grep, and glob for file discovery and path validation.
  • [REMOTE_CODE_EXECUTION]: The skill performs a clone of a remote Git repository; however, it includes strict constraints that the agent must never execute or import any of the downloaded code, using it exclusively for path discovery and documentation lookup.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:30 PM
Security Audit — agent-trust-hub — physicsnemo-discover