compileiq-booster-pack
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches Booster Pack archives and manifest files from NVIDIA's official GitHub Releases (NVIDIA/CompileIQ).
- [COMMAND_EXECUTION]: The benchmarking utility scripts/apply_one_acf.sh utilizes eval to run the baseline and candidate performance measurement commands provided by the user or agent.
- [DYNAMIC_EXECUTION]: Employs Python string execution (python -c) to perform numerical calculations and validation checks on benchmark results throughout the optimization process.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external manifest data (booster-pack-manifest.json) and optimization configs from downloaded zips, which are then used to construct shell commands and Python execution logic.
- Ingestion points: booster-pack-manifest.json, booster-pack-catalog.json, and .acf files from the downloaded archives.
- Boundary markers: Not present; the agent processes the content as structured configuration data.
- Capability inventory: Shell command execution via eval in the benchmarking script and file system writes to booster-pack-log.csv.
- Sanitization: None; the skill assumes the integrity of the vendor-provided optimization configurations.
Audit Metadata