skills/robium-ai/robium/ros2/Gen Agent Trust Hub

ros2

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill documents the use of sudo rosdep init in references/workspace-and-packages.md. This is a standard administrative procedure for initializing the ROS 2 dependency manager, but it requires the execution of commands with root privileges.
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns for parameterizing nodes where data is ingested from external sources such as command-line arguments, launch configurations, and YAML files.
  • Ingestion points: External data enters the system through LaunchConfiguration in examples/package-ament-python/launch/talker.launch.py and declare_parameter calls in examples/package-ament-python/ros2_example_pkg/talker_node.py.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore malicious content within these data streams.
  • Capability inventory: The skill context includes the ability to compile and execute code using colcon and ros2 run as described in SKILL.md.
  • Sanitization: No sanitization or validation logic is present for the data processed via ROS parameters in the provided code examples.
  • [DATA_EXFILTRATION]: The skill includes a curl command to http://192.168.186.2/api/restart-app in SKILL.md to manage a local robot base. While this is a functional requirement for interacting with TurtleBot 4 hardware, it involves network communication to a non-whitelisted local-range IP address.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 04:08 AM
Security Audit — agent-trust-hub — ros2