simready-foundation-conform-fet-004-mujoco

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and process data from external, potentially untrusted sources including validation reports, profile TOML files, and user requests.\n
  • Ingestion points: Workflow Step 1 in SKILL.md identifies validation reports and profile TOMLs as input.\n
  • Boundary markers: No specific delimiters or warnings to ignore embedded instructions are provided in the instructions.\n
  • Capability inventory: The skill allows for modifying USD files and executing the workspace upgrade command.\n
  • Sanitization: No sanitization or validation logic for the ingested reports is described.\n- [COMMAND_EXECUTION]: The skill references the execution of the workspace upgrade command as part of the feature adapter workflow, which is an internal NVIDIA tool for asset management.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:22 PM
Security Audit — agent-trust-hub — simready-foundation-conform-fet-004-mujoco