cuopt-server-api-python

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references official nvidia/cuopt Docker images and requires the requests Python library. These resources are standard for the intended optimization tasks and are sourced from the vendor's official registries.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for ingesting data from an external server response.
  • Ingestion points: The reqId is ingested from the JSON response of a POST request to /cuopt/request (documented in SKILL.md and implemented in the client scripts within the assets/ directory).
  • Boundary markers: The documentation specifically recommends validating the ID, and the provided client scripts implement this validation before using the ID in URL interpolation.
  • Capability inventory: The skill uses the requests library for subsequent GET calls to retrieve results from the server.
  • Sanitization: External input is sanitized using a regular expression (re.fullmatch(r"[A-Za-z0-9_-]{1,64}", req_id)) which restricts the character set and length of the injected string, mitigating potential injection or path traversal risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:15 PM
Security Audit — agent-trust-hub — cuopt-server-api-python