nvidia-cuopt-install
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches software packages and Docker images from official NVIDIA repositories, including pypi.nvidia.com and Docker Hub.
- [COMMAND_EXECUTION]: Provides instructions for using standard system tools like pip, conda, docker, nvidia-smi, find, and gcc for installation and environment verification.
- [PROMPT_INJECTION]: The skill ingests user input (CUDA major version, preferred interface, and package manager) into the installation workflow, presenting an indirect prompt injection surface. Ingestion points: SKILL.md (Required questions). Boundary markers: Absent. Capability inventory: Package installation and shell command execution via user-facing instructions in SKILL.md and resources/verification_examples.md. Sanitization: Absent.
- [SAFE]: The skill aligns with its stated purpose of software installation for a well-known library, uses trusted sources, and avoids malicious behaviors such as automated script execution or sensitive data exfiltration.
Audit Metadata