nvidia-cuopt-install

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches software packages and Docker images from official NVIDIA repositories, including pypi.nvidia.com and Docker Hub.
  • [COMMAND_EXECUTION]: Provides instructions for using standard system tools like pip, conda, docker, nvidia-smi, find, and gcc for installation and environment verification.
  • [PROMPT_INJECTION]: The skill ingests user input (CUDA major version, preferred interface, and package manager) into the installation workflow, presenting an indirect prompt injection surface. Ingestion points: SKILL.md (Required questions). Boundary markers: Absent. Capability inventory: Package installation and shell command execution via user-facing instructions in SKILL.md and resources/verification_examples.md. Sanitization: Absent.
  • [SAFE]: The skill aligns with its stated purpose of software installation for a well-known library, uses trusted sources, and avoids malicious behaviors such as automated script execution or sensitive data exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 09:13 AM
Security Audit — agent-trust-hub — nvidia-cuopt-install