build-and-dependency

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate development environment setup instructions including container management and dependency resolution using uv.- [EXTERNAL_DOWNLOADS]: Fetches official Docker images from NVIDIA's Container Registry (nvcr.io) and clones the project source code from the author's official GitHub repository. These are trusted sources consistent with the skill's purpose.- [COMMAND_EXECUTION]: Provides shell commands for environment configuration, repository initialization, and containerized execution. These commands are standard for the described workflow and do not involve suspicious execution patterns like piping remote scripts to a shell.- [DATA_EXFILTRATION]: No sensitive file access or network exfiltration patterns were found. The practice of mounting the uv cache directory is a standard performance optimization for package management.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 07:46 AM
Security Audit — agent-trust-hub — build-and-dependency