simready-foundation-conform-fet-003-physx
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from external sources including validation reports, profile TOML files, and user requests.
- Ingestion points: Identification of feature versions and failing requirements occurs via validation reports, profiles, and user-supplied text (as described in the Workflow section of
SKILL.md). - Boundary markers: The instructions do not specify the use of delimiters or explicit warnings to ignore embedded instructions within the ingested data.
- Capability inventory: The skill involves reading local manifest files (
nv_core/...), writing repairs to staged output assets, and executing command-line tools for upgrades and validation. - Sanitization: There is no explicit mention of sanitization or validation of the input data before it influences the agent's actions.
- [COMMAND_EXECUTION]: The skill requires the agent to execute shell commands to perform its primary function.
- Evidence: The
SKILL.mdfile instructs the agent to use theworkspace upgradecommand for authoring runtime-specific data and to "rerun the same profile gate or the narrowest available feature/capability validation gate" to verify repairs. While these are intended for local development workflows, they involve executing subprocesses based on configurations derived from potentially untrusted inputs.
Audit Metadata