simready-foundation-conform-fet-000-standard

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run apply-simready-foundation-metadata and validate-simready-profile using the uv runner. These tools are specific to the NVIDIA SimReady foundation and are used for asset metadata repair and conformance validation.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from validation reports (JSON/Markdown) and USD assets to identify and fix conformance issues. This creates an attack surface where instructions could theoretically be embedded in the processed data.
  • Ingestion points: usd_asset, validation_report, and FET_000_STANDARD manifest files located in the repository.
  • Boundary markers: The instructions lack specific delimiters or "ignore embedded instructions" warnings when processing the contents of external reports.
  • Capability inventory: The skill possesses file-write capabilities for staging repaired assets and shell execution capabilities via uv run for validation tasks.
  • Sanitization: No explicit sanitization, filtering, or escaping of the content within the ingested validation reports is defined in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:22 PM
Security Audit — agent-trust-hub — simready-foundation-conform-fet-000-standard