rerun
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the
rerun-sdkandgradio_rerunPython packages usinguvorpip, and thererun-clitool usingcargo. These are standard tools for the Rerun visualization ecosystem. - [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to visualize external data, such as LeRobot episodes and custom sensor streams. This creates a surface for indirect prompt injection where adversarial data embedded in a dataset could attempt to influence the agent's behavior during the visualization process.
- Ingestion points: Data enters the context through
lerobot-dataset-vizandrr.log()calls processing external sensor streams or datasets (SKILL.md). - Boundary markers: The skill does not explicitly define delimiters or instructions to ignore embedded content within the data streams.
- Capability inventory: The skill uses subprocess calls to execute visualization commands and Python scripts for data logging (SKILL.md).
- Sanitization: No specific sanitization or validation logic for the ingested data is described in the skill instructions.
Audit Metadata