simready-foundation-conform-fet-007-nonvisual-materials

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a structured workflow for material conformance repairs. It includes instructions for inspecting and modifying USD attributes using standard APIs and local validation commands. All procedures follow documented best practices for asset staging and repair.
  • [COMMAND_EXECUTION]: The skill instructs the agent to run a validation command (uv run validate-simready-profile) to verify asset conformance. This is a legitimate use of a local project-specific tool for validation and does not involve remote script execution from untrusted sources.
  • [PROMPT_INJECTION]: The skill involves processing user-provided USD assets (usd_asset), which is an ingestion point for external data. While this presents a surface for indirect prompt injection, the skill limits its operations to material attribute repair and uses structured USD property modification rather than raw text processing, which significantly reduces the risk.
  • Ingestion points: usd_asset input parameter in SKILL.md.
  • Boundary markers: None explicitly defined for preventing instruction following from USD content.
  • Capability inventory: File system modification within output_root and command execution for validation in SKILL.md.
  • Sanitization: The skill relies on structured USD API calls to author tokens, providing inherent validation against arbitrary text injection in the output.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 05:57 AM
Security Audit — agent-trust-hub — simready-foundation-conform-fet-007-nonvisual-materials