fhe-application-design

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill retrieves a specialized Docker image (ghcr.io/niobiuminc/fhe-dev) and clones the niobium-client repository from GitHub. These downloads are necessary to provision the development toolchain and are hosted on the vendor's official distribution channels.
  • [COMMAND_EXECUTION]: The methodology involves executing shell commands to build C++ binaries and run tests. These operations facilitate the compilation of FHE circuits and the validation of encrypted computations against plaintext references.
  • [CREDENTIALS_UNSAFE]: The skill manages authentication for its cloud deployment component through a credentials file located at ~/.fog/credentials or an environment variable. This is a standard implementation for secure access to the vendor's Niobium Fog platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on external data and machine learning models, creating a surface for indirect prompt injection. To address this, the instructions mandate clear separation of trust boundaries, the use of dedicated client/server binaries, and the implementation of input-bounds enforcement on the client side.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 12:35 AM
Security Audit — agent-trust-hub — fhe-application-design