simready-foundation-conform-fet-024-physx
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill workflow is driven by data ingested from external manifest files and markdown documentation. This creates a vulnerability surface where a maliciously crafted manifest could influence the agent's behavior.
- Ingestion points: The skill reads
FET_024_PHYSX-0.1.0.jsonandFET_024_PHYSX.mdfrom thenv_coredirectory tree. - Boundary markers: The instructions do not define clear delimiters or provide instructions for the agent to ignore natural language instructions that might be embedded within the JSON manifest or documentation.
- Capability inventory: The skill is authorized to read local configuration files and perform edits on assets or packages, providing a path for the agent to take actions based on potentially poisoned input.
- Sanitization: There is no evidence of schema validation or content sanitization performed on the manifest files before they are interpreted by the agent.
Audit Metadata