skills/nvidia/cuopt/cuopt-developer/Gen Agent Trust Hub

cuopt-developer

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate development environment for the NVIDIA cuOpt codebase, provided by the official vendor. It focuses on internal solver mechanics, CI/CD workflows, and developer conventions.
  • [PROMPT_INJECTION]: The skill contains 'Refusal Rules' that strengthen the agent's safety posture by explicitly forbidding privileged operations and unauthorized branch pushes, even if requested by the user. These instructions reinforce the agent's alignment with security best practices.
  • [COMMAND_EXECUTION]: The skill permits standard development commands (git, conda, pytest, ctest, ./build.sh) within the user's workspace, which is expected for its primary purpose. It includes specific guidance on parallelization to prevent resource exhaustion (OOM).
  • [EXTERNAL_DOWNLOADS]: The skill guides the agent to fetch project configurations and datasets from trusted official repositories (e.g., NVIDIA, RAPIDS), following standard open-source development practices. It warns against third-party untrusted sources.
  • [INDIRECT_PROMPT_INJECTION]: While the skill involves processing external data such as code and PR content, it includes specific behavior rules to 'Clarify Before Assuming' and 'Sanitize Internal Context,' which act as safeguards against data leakage and accidental obedience to embedded instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:19 PM
Security Audit — agent-trust-hub — cuopt-developer