ros2
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill documents the use of
sudo rosdep initinreferences/workspace-and-packages.md. This is a standard administrative procedure for initializing the ROS 2 dependency manager, but it requires the execution of commands with root privileges. - [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns for parameterizing nodes where data is ingested from external sources such as command-line arguments, launch configurations, and YAML files.
- Ingestion points: External data enters the system through
LaunchConfigurationinexamples/package-ament-python/launch/talker.launch.pyanddeclare_parametercalls inexamples/package-ament-python/ros2_example_pkg/talker_node.py. - Boundary markers: The instructions do not define specific delimiters or instructions to ignore malicious content within these data streams.
- Capability inventory: The skill context includes the ability to compile and execute code using
colconandros2 runas described inSKILL.md. - Sanitization: No sanitization or validation logic is present for the data processed via ROS parameters in the provided code examples.
- [DATA_EXFILTRATION]: The skill includes a
curlcommand tohttp://192.168.186.2/api/restart-appinSKILL.mdto manage a local robot base. While this is a functional requirement for interacting with TurtleBot 4 hardware, it involves network communication to a non-whitelisted local-range IP address.
Audit Metadata