skills/nvidia/simready-foundation/simready-foundation-conform-fet-024-base-articulation/Gen Agent Trust Hub
simready-foundation-conform-fet-024-base-articulation
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute the
validate-simready-profilecommand-line tool using theuvpackage manager. This tool is part of the vendor's Physical AI Skill Hub and is used to verify the compliance of repaired assets. - [PROMPT_INJECTION]: The skill processes untrusted input from USD files and external validation reports to drive its decision-making logic, creating a surface for indirect prompt injection.
- Ingestion points: External USD assets (
usd_asset) and validation reports (validation_report) are loaded into the agent's context for analysis and repair. - Boundary markers: The instructions do not specify the use of clear delimiters or XML tags to isolate untrusted asset data from the skill's operational instructions.
- Capability inventory: The skill has the capability to execute shell commands (
uv run) and perform file system operations within the workspace. - Sanitization: There is no explicit requirement for the agent to sanitize or validate the integrity of the content within the USD files or the reports prior to processing.
Audit Metadata