simready-foundation-conform-fet-000-physx
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external USD assets (usd_asset) and override data (physx_overrides) which are untrusted inputs. 1. Ingestion points: usd_asset and physx_overrides files specified in SKILL.md. 2. Boundary markers: No explicit delimiters or warnings to ignore embedded instructions are provided for the processed assets. 3. Capability inventory: The skill performs filesystem writes to staged output and executes local build and validation commands via repo.bat (subprocess execution). 4. Sanitization: The skill does not mention sanitizing or validating the content of external USD files to mitigate potential prompt injection attacks.
Audit Metadata