tao-train-dino

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides command templates and configuration schemas to guide the agent in executing shell commands for model training and deployment using Docker and the dino CLI tool. Evidence is found in references/tao-deploy-dino.md and references/skill_info.yaml.
  • [EXTERNAL_DOWNLOADS]: The skill references datasets and container images hosted on NVIDIA-controlled infrastructure. Evidence includes references to s3://nvcf-storage-handling/ for training data and nvcr.io/nvidia/tao/ for tool containers in SKILL.md and references/tao-deploy-dino.md.
  • [PROMPT_INJECTION]: The skill specifies ingestion of external data files (COCO JSON) which presents a surface for indirect prompt injection, though this is typical for machine learning training tasks. Ingestion points: dataset URIs defined in SKILL.md and references/dino-data-specs.md. Boundary markers: None explicitly defined for file contents. Capability inventory: execution of the dino CLI and docker run commands as described in references/skill_info.yaml. Sanitization: relies on the internal parsing logic of the TAO Toolkit.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 05:49 PM
Security Audit — agent-trust-hub — tao-train-dino