simready-foundation-conform-fet-024-physx

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill workflow is driven by data ingested from external manifest files and markdown documentation. This creates a vulnerability surface where a maliciously crafted manifest could influence the agent's behavior.
  • Ingestion points: The skill reads FET_024_PHYSX-0.1.0.json and FET_024_PHYSX.md from the nv_core directory tree.
  • Boundary markers: The instructions do not define clear delimiters or provide instructions for the agent to ignore natural language instructions that might be embedded within the JSON manifest or documentation.
  • Capability inventory: The skill is authorized to read local configuration files and perform edits on assets or packages, providing a path for the agent to take actions based on potentially poisoned input.
  • Sanitization: There is no evidence of schema validation or content sanitization performed on the manifest files before they are interpreted by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:22 PM
Security Audit — agent-trust-hub — simready-foundation-conform-fet-024-physx