simready-foundation-create-package
Warn
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
assets/scripts/sr_pkg_sample/_conformance_writer.pyemploys theeval()function to parse string representations of feature dependencies and failing requirements within thebuild_asset_resultsfunction. This practice is unsafe as it could lead to arbitrary code execution if the input strings, originating from asset validation reports, are maliciously crafted. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves processing untrusted USD and USDA files to generate metadata and conformance JSON files.
- Ingestion points: USD assets are read from user-provided source directories during the
pre_validatephase. - Boundary markers: The skill does not implement explicit delimiters or safety warnings to separate untrusted asset content from the agent's internal instructions.
- Capability inventory: The skill has the capability to write files (BOM, conformance metadata, package definitions) via
Path.write_textandwrapp_write_file_content, and to execute repository operations via the WRAPP CLI. - Sanitization: While output is formatted as JSON, the parsing of input summaries lacks sanitization, relying on unsafe execution methods like
eval(). - [EXTERNAL_DOWNLOADS]: The environment setup script
assets/scripts/setup_venv.shand the associated requirements file fetch Python packages from a vendor-specific index athttps://pypi.nvidia.com/. While this represents a resource owned by the skill's authoring organization, the automated installation of external dependencies remains a security-sensitive operation. - [COMMAND_EXECUTION]: The skill orchestrates complex packaging workflows that include calling the WRAPP command-line tool and managing virtual environments. These operations involve file system modifications and potential network communication with asset repositories.
Audit Metadata