tao-train-mask-auto-label
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted dataset content and configuration specs. * Ingestion points: Dataset directories and annotation paths defined in SKILL.md and references/skill_info.yaml. * Boundary markers: Absent in the command construction logic. * Capability inventory: Executes mal commands within Docker containers using the Bash tool. * Sanitization: Not explicitly implemented in the skill's instructions.
- [SAFE]: The skill uses official vendor-managed container images from nvcr.io to execute its operations, following standard security practices for tool isolation.
Audit Metadata