tao-train-grounding-dino

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Executes the grounding_dino command-line utility within Docker containers for training, evaluation, and inference tasks. This behavior is consistent with the primary purpose of the skill for the NVIDIA TAO Toolkit.
  • [EXTERNAL_DOWNLOADS]: Mentions downloading pre-trained BERT weights from the Hugging Face Hub and utilizes official NVIDIA TAO Toolkit Docker images from the NVIDIA Container Registry (nvcr.io). These are well-known and reputable services.
  • [SAFE]: No malicious patterns, prompt injections, or unauthorized data access were detected. The skill's operations are transparent and well-documented for its intended use case in open-vocabulary object detection.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data including image datasets and text captions for open-set detection. While this represents an attack surface, it is fundamental to the model's language-guided detection capability and is handled by the vendor's containerized infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 05:48 PM
Security Audit — agent-trust-hub — tao-train-grounding-dino