Scanned skills

nvidia/skills omniverse-cad-to-simready

Checked the catalogued skill at omniverse-cad-to-simready.

SkillTrust corpus scan 19 September 2026 v0.10.0 via skillsh Verify on GitHub
F AI-triaged 50
F Security

F; retained sample includes a high finding · SD-007 · what this rule accepts as a false positive →

D Permissions

D set by findings not listed

B Transparency

B; retained sample includes a medium finding · SD-007 · what this rule accepts as a false positive →

showing 10 of 50
securityhigh SD-007
references/content-agents/scripts/content_agent_client.py
transparencymedium SD-007
references/content-agents/scripts/report_schema.json
transparencymedium SD-007
references/identify-asset-context/scripts/report_schema.json
transparencymedium SD-007
references/omni-asset-validate-physics/scripts/report_schema.json
transparencymedium SD-007
references/omni-asset-validate/scripts/report_schema.json
transparencymedium SD-007
references/ovrtx-render-service/scripts/report_schema.json
securityhigh SD-007
references/ovrtx-render-service/scripts/run.py
securityhigh SD-022
references/preflight/README.md
securityhigh SD-022
references/preflight/README.md
securityhigh SD-007
references/preflight/README.md
30 suppressed by AI triage
transparencymedium SD-007 benign_example
evals/evals.json

The entry merely references a custom OpenAI-compatible endpoint and does not represent an executable outbound network call or broad permission grant.

securityhigh SD-007 benign_example
evals/evals.json

The entry lists existing local service URLs as configuration, not an executable network call or permission granting outbound traffic.

transparencymedium SD-007 benign_example
references/assemble-package-source/scripts/report_schema.json

The line references a JSON schema URL, not an executable outbound network call or permission grant.

transparencymedium SD-007 benign_example
references/content-agents/references/material-agent-client/scripts/report_schema.json

Schema reference URL is a benign configuration reference, not an outbound network call

permission_hygienehigh SD-003 benign_example
references/content-agents/references/physics-agent-client/README.md

The path appears only in documentation and does not represent executable code that could traverse the file system.

transparencymedium SD-007 benign_example
references/content-agents/references/physics-agent-client/scripts/report_schema.json

Schema reference URL is a benign configuration reference, not an outbound network call

transparencymedium SD-007 benign_example
references/content-agents/references/texture-agent-client/scripts/report_schema.json

Schema reference URL is a benign configuration reference, not an outbound network call

permission_hygienehigh SD-003 benign_example
references/content-agents/scripts/content_agent_client.py

Path check explicitly allows only /var/... prefixes, preventing traversal.

permission_hygienehigh SD-003 benign_example
references/content-agents/scripts/content_agent_client.py

Path check explicitly allows only /var/... prefixes, preventing traversal.

permission_hygienehigh SD-003 benign_example
references/content-agents/scripts/content_agent_client.py

Path check explicitly allows only /var/... prefixes, preventing traversal.

permission_hygienehigh SD-003 benign_example
references/content-agents/scripts/content_agent_client.py

Path check explicitly allows only /var/... prefixes, preventing traversal.

permission_hygienehigh SD-003 benign_example
references/content-agents/scripts/content_agent_client.py

Path check explicitly allows only /var/... prefixes, preventing traversal.

permission_hygienehigh SD-003 benign_example
references/content-agents/scripts/content_agent_client.py

Path check explicitly allows only /var/... prefixes, preventing traversal.

transparencymedium SD-007 benign_example
references/content-agents/scripts/content_agent_report_schema.json

Schema reference URL is a benign configuration reference, not an outbound network call

transparencymedium SD-007 benign_example
references/convert-to-usd/references/mujoco-usd-converter/scripts/report_schema.json

Reference to JSON schema, not an executed outbound network call

transparencymedium SD-007 benign_example
references/convert-to-usd/references/urdf-usd-converter/scripts/report_schema.json

The JSON schema reference is a normal configuration and does not execute or grant outbound network calls.

transparencymedium SD-007 benign_example
references/convert-to-usd/references/usd-convert-cad/scripts/report_schema.json

References a public JSON schema, no active network request

securityhigh SD-007 benign_example
references/convert-to-usd/references/usd-convert-cad/scripts/run.py

Only a static URL reference, not an outbound call or permission grant.

securityhigh SD-007 benign_example
references/convert-to-usd/references/usd-convert-cad/scripts/run.py

Only a static URL reference, not an outbound call or permission grant.

securityhigh SD-007 benign_example
references/convert-to-usd/references/usd-convert-cad/scripts/run.py

Only a static URL reference, not an outbound call or permission grant.

transparencymedium SD-007 benign_example
references/convert-to-usd/references/usd-convert-gsplat/scripts/report_schema.json

The $schema URL is a metadata reference for a JSON schema and does not trigger an outbound network call.

securityhigh SD-007 benign_example
references/convert-to-usd/references/usd-convert-gsplat/scripts/run.py

The code merely assigns a URL string to a variable; no outbound network call is made.

transparencymedium SD-007 benign_example
references/convert-to-usd/scripts/report_schema.json

The file only declares a schema URL, not performing an outbound network call.

transparencymedium SD-007 benign_example
references/nv-core-package-sample-validation/scripts/report_schema.json

Referencing the JSON‑schema.org URL is a normal configuration for schema validation and does not initiate an outbound network call.

transparencymedium SD-007 benign_example
references/nv-core-package-sample/scripts/report_schema.json

Referencing the JSON‑schema.org URL is a normal configuration for schema validation and does not initiate an outbound network call.

transparencymedium SD-007 benign_example
references/omni-asset-validate-geometry/scripts/report_schema.json

This is only a JSON schema reference, not an executable network call or permission grant.

securityhigh SD-007 benign_example
references/ovrtx-render-service/scripts/run.py

The code only imports urllib modules; no outbound call is made here, which is standard library usage.

securitymedium SD-008 benign_example
references/ovrtx-render-service/scripts/run.py

Decoding a base64 PNG payload is typical image handling, not obfuscation.

transparencymedium SD-007 benign_example
references/simready-conform-profile/references/FET_000_CORE/scripts/report_schema.json

Reference to the standard JSON Schema URL is a normal configuration, not an active network call.

transparencymedium SD-007 benign_example
shared/simready_package_report_schema.json

Referencing the JSON‑schema.org URL is a normal configuration for schema validation and does not initiate an outbound network call.