nemo-rl-session-memory

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Authenticity and Integrity. The skill includes a Sigstore/in-toto digital signature bundle (skill.oms.sig) from NVIDIA Corporation, verifying that the skill originates from a trusted source and has not been tampered with.
  • [SAFE]: Command Execution. The instructions use common, non-privileged shell commands like 'mkdir', 'ls', and 'date' and git queries like 'git status' and 'git branch'. These are used appropriately for managing session metadata in a local directory.
  • [SAFE]: Data Handling. The skill explicitly instructs agents not to store secrets, tokens, or private credentials in session files. It also implements a safety measure by requiring agents to verify information from session files against the actual ground truth of the repository before acting.
  • [SAFE]: Metadata and Best Practices. The evaluation benchmark provided with the skill confirms it was tested against security and correctness metrics, achieving a 100% security score. Minor documentation omissions noted in the benchmark do not pose security risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 01:44 AM
Security Audit — agent-trust-hub — nemo-rl-session-memory