simready-foundation-validate-foundation-change

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of repository diffs and manifests to perform consistency audits.
  • Ingestion points: User-provided file lists and contents via changed_files and target_feature_profile in SKILL.md.
  • Boundary markers: Absent; the instructions do not define specific delimiters for separating user-provided data from agent instructions.
  • Capability inventory: The agent is instructed to run local tools such as simready-validate, USD/PXR, and Python syntax checkers.
  • Sanitization: Absent; the skill does not explicitly describe filtering or sanitizing the input data before processing.
  • [COMMAND_EXECUTION]: The instructions direct the agent to execute local validation commands including simready-validate, USD/PXR, and Python syntax/import checks. These are standard operations for the skill's auditing and validation purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:22 PM
Security Audit — agent-trust-hub — simready-foundation-validate-foundation-change