compileiq-booster-pack

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches Booster Pack archives and manifest files from NVIDIA's official GitHub Releases (NVIDIA/CompileIQ).
  • [COMMAND_EXECUTION]: The benchmarking utility scripts/apply_one_acf.sh utilizes eval to run the baseline and candidate performance measurement commands provided by the user or agent.
  • [DYNAMIC_EXECUTION]: Employs Python string execution (python -c) to perform numerical calculations and validation checks on benchmark results throughout the optimization process.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external manifest data (booster-pack-manifest.json) and optimization configs from downloaded zips, which are then used to construct shell commands and Python execution logic.
  • Ingestion points: booster-pack-manifest.json, booster-pack-catalog.json, and .acf files from the downloaded archives.
  • Boundary markers: Not present; the agent processes the content as structured configuration data.
  • Capability inventory: Shell command execution via eval in the benchmarking script and file system writes to booster-pack-log.csv.
  • Sanitization: None; the skill assumes the integrity of the vendor-provided optimization configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:25 PM
Security Audit — agent-trust-hub — compileiq-booster-pack