simready-foundation-conform-fet-003-newton

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external inputs like validation reports and user requests to drive asset repairs. This creates a surface where instructions embedded in those reports could influence agent actions. * Ingestion points: Workflow steps in SKILL.md specify identifying features and loading manifests from reports and user requests. * Boundary markers: The instructions lack explicit markers to isolate instructions from the data being processed. * Capability inventory: The agent is instructed to modify USD files (repairs) and execute validation tools (commands). * Sanitization: No specific sanitization methods for report content are provided.
  • [COMMAND_EXECUTION]: The instructions direct the agent to execute tools such as workspace upgrade and validation gates as part of the conformance workflow. These are internal development commands.
  • [NO_CODE]: The skill contains only documentation, metadata, and instructional markdown; it does not include any executable scripts or binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:22 PM
Security Audit — agent-trust-hub — simready-foundation-conform-fet-003-newton