environments
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run
npx robium-ai doctor --jsonto inspect the host environment's capabilities, such as platform architecture, Docker daemon state, and GPU availability. This utility is a tool provided by the skill's vendor to facilitate environment decisions. - [PRIVILEGE_ESCALATION]: Documentation and reference files provide administrative commands using
sudofor system configuration tasks. These include installing the NVIDIA Container Toolkit, configuring the Docker runtime, and managing network interfaces viaifconfigandnetplan. These operations are consistent with the skill's primary purpose of configuring development and runtime environments. - [EXTERNAL_DOWNLOADS]: The skill's Docker examples and instructions reference external binaries and images from official, well-known sources. These include fetching the
uvbinary from the Astral-sh GitHub Container Registry and utilizing official base images for ROS and NVIDIA CUDA from Docker Hub. - [INDIRECT_PROMPT_INJECTION]: The skill involves processing data from external system reports which represents a potential attack surface.
- Ingestion points: The agent reads JSON output from the
robium-ai doctorcommand as specified in SKILL.md. - Boundary markers: The instructions do not specify explicit delimiters or "ignore instructions" warnings when processing the tool's output.
- Capability inventory: The skill documentation includes subprocess calls for environment management, Docker execution, and file-write operations to the project's architecture brief.
- Sanitization: There is no explicit mention of sanitizing or validating the system report data before it is incorporated into the agent's decision-making context.
Audit Metadata