tao-generate-image-grounding

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill pulls a Docker container image from nvcr.io/nvstaging/tao/tao-toolkit-pyt, which is the official NVIDIA registry.
  • [EXTERNAL_DOWNLOADS]: Instructions in references/vllm_server.md describe downloading the vllm-openai image from Docker Hub and installing the vllm package via pip from the official vLLM project.
  • [COMMAND_EXECUTION]: The skill executes the auto_label command to run the grounding pipeline and provides instructions for running docker and vllm commands to host inference servers.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-supplied image captions from an input JSONL file using a Vision-Language Model. While no specific sanitization or boundary markers are documented, this is the core intended functionality of the skill for data annotation purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:56 AM
Security Audit — agent-trust-hub — tao-generate-image-grounding