tao-train-mask-auto-encoder

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted dataset content and configuration overrides, creating a potential surface for indirect prompt injection.
  • Ingestion points: Data enters the process via the dataset.train_data_sources, dataset.val_data_sources, and dataset.test_data_sources parameters defined in SKILL.md and references/skill_info.yaml.
  • Boundary markers: The documentation does not provide specific instructions or delimiters to delineate untrusted input from the system prompts or model configurations.
  • Capability inventory: The skill has the capability to execute mae CLI commands and docker run operations, which could be exploited if malicious instructions within the dataset are processed (see references/skill_info.yaml).
  • Sanitization: There are no mentioned mechanisms for sanitizing or validating the contents of the image archives or folders provided as data sources.
  • [EXTERNAL_DOWNLOADS]: The skill uses official NVIDIA container images from a well-known service.
  • Evidence: SKILL.md and references/tao-deploy-mask-auto-encoder.md reference container images from the NVIDIA Container Registry at nvcr.io.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:56 AM
Security Audit — agent-trust-hub — tao-train-mask-auto-encoder