simready-foundation-conform-fet-003-physx

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from external sources including validation reports, profile TOML files, and user requests.
  • Ingestion points: Identification of feature versions and failing requirements occurs via validation reports, profiles, and user-supplied text (as described in the Workflow section of SKILL.md).
  • Boundary markers: The instructions do not specify the use of delimiters or explicit warnings to ignore embedded instructions within the ingested data.
  • Capability inventory: The skill involves reading local manifest files (nv_core/...), writing repairs to staged output assets, and executing command-line tools for upgrades and validation.
  • Sanitization: There is no explicit mention of sanitization or validation of the input data before it influences the agent's actions.
  • [COMMAND_EXECUTION]: The skill requires the agent to execute shell commands to perform its primary function.
  • Evidence: The SKILL.md file instructs the agent to use the workspace upgrade command for authoring runtime-specific data and to "rerun the same profile gate or the narrowest available feature/capability validation gate" to verify repairs. While these are intended for local development workflows, they involve executing subprocesses based on configurations derived from potentially untrusted inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:22 PM
Security Audit — agent-trust-hub — simready-foundation-conform-fet-003-physx