fhe-application-design
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill retrieves a specialized Docker image (
ghcr.io/niobiuminc/fhe-dev) and clones theniobium-clientrepository from GitHub. These downloads are necessary to provision the development toolchain and are hosted on the vendor's official distribution channels. - [COMMAND_EXECUTION]: The methodology involves executing shell commands to build C++ binaries and run tests. These operations facilitate the compilation of FHE circuits and the validation of encrypted computations against plaintext references.
- [CREDENTIALS_UNSAFE]: The skill manages authentication for its cloud deployment component through a credentials file located at
~/.fog/credentialsor an environment variable. This is a standard implementation for secure access to the vendor's Niobium Fog platform. - [INDIRECT_PROMPT_INJECTION]: The skill operates on external data and machine learning models, creating a surface for indirect prompt injection. To address this, the instructions mandate clear separation of trust boundaries, the use of dedicated client/server binaries, and the implementation of input-bounds enforcement on the client side.
Audit Metadata