tao-train-mask-auto-label

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted dataset content and configuration specs. * Ingestion points: Dataset directories and annotation paths defined in SKILL.md and references/skill_info.yaml. * Boundary markers: Absent in the command construction logic. * Capability inventory: Executes mal commands within Docker containers using the Bash tool. * Sanitization: Not explicitly implemented in the skill's instructions.
  • [SAFE]: The skill uses official vendor-managed container images from nvcr.io to execute its operations, following standard security practices for tool isolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:56 AM
Security Audit — agent-trust-hub — tao-train-mask-auto-label