cuopt-server-api-python
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references official
nvidia/cuoptDocker images and requires therequestsPython library. These resources are standard for the intended optimization tasks and are sourced from the vendor's official registries. - [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for ingesting data from an external server response.
- Ingestion points: The
reqIdis ingested from the JSON response of a POST request to/cuopt/request(documented inSKILL.mdand implemented in the client scripts within theassets/directory). - Boundary markers: The documentation specifically recommends validating the ID, and the provided client scripts implement this validation before using the ID in URL interpolation.
- Capability inventory: The skill uses the
requestslibrary for subsequent GET calls to retrieve results from the server. - Sanitization: External input is sanitized using a regular expression (
re.fullmatch(r"[A-Za-z0-9_-]{1,64}", req_id)) which restricts the character set and length of the injected string, mitigating potential injection or path traversal risks.
Audit Metadata