node-rca-rcca

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the official nvfleetint CLI to retrieve node health and alert data. These commands are correctly configured to use JSON output for predictable parsing and include read-only safety warnings for most operations.
  • [EXTERNAL_DOWNLOADS]: The skill references the official NVIDIA GitHub repository for client releases. This is a trusted source associated with the skill's author and serves a legitimate functional purpose.
  • [DATA_EXFILTRATION]: The skill includes a dedicated step for research that explicitly forbids the inclusion of hostnames, UUIDs, or tenant data in web search queries, effectively preventing the leakage of sensitive environment metadata to external services.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes external alert data, it mitigates injection risks by requiring strict schema validation of API responses and semantic HTML escaping of all dynamic values integrated into the final report artifacts.
  • [PRIVILEGE_ESCALATION]: The workspace management workflow uses a restrictive umask 077 and private temporary directories to ensure that diagnostic data and report files are not accessible to other users on the host system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 07:02 AM
Security Audit — agent-trust-hub — node-rca-rcca