nemo-rl-brev-etiquette

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill provides operational best practices for storage and secret management on Brev instances, which is consistent with standard developer workflows for this platform.
  • [COMMAND_EXECUTION]: The skill includes shell snippets for directory organization and environment variable configuration. These commands are restricted to standard workspace and ephemeral volume paths.
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it ingests untrusted data from a local file. Ingestion points: /home/ubuntu/RL/.env in SKILL.md. Boundary markers: Absent. Capability inventory: Directory creation (mkdir) and environment variable exports in SKILL.md. Sanitization: Absent. While this is a common development pattern, the lack of isolation for external config values represents a potential surface, though mitigated by the skill's explicit safety warnings.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 07:46 AM
Security Audit — agent-trust-hub — nemo-rl-brev-etiquette