fleet-health-report
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
nvfleetintCLI to perform various read-only operations such as listing compute zones, node groups, and active alerts to build a status report. - [EXTERNAL_DOWNLOADS]: The documentation references the official NVIDIA repository for Fleet Intelligence client releases. This is a legitimate resource from the skill vendor.
- [CREDENTIALS_UNSAFE]: The instructions provide guidance on managing authentication profiles and service keys using secure CLI prompts and status checks, explicitly instructing users never to hardcode or expose API keys.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external API responses via the CLI. It mitigates potential injection risks in the generated HTML report by mandating HTML-escaping for all dynamic values and utilizing a predefined internal theme.
- [PRIVILEGE_ESCALATION]: Employs secure coding practices by creating restricted temporary directories for data capture and validating file permissions before performing cleanup operations.
Audit Metadata