nvfleetint
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs users to obtain binary releases from the official GitHub repository for the NVIDIA Fleet Intelligence Client. These resources are hosted by a well-known service and provided by the official vendor.
- [COMMAND_EXECUTION]: The skill relies on the execution of the
nvfleetintcommand-line tool. The agent uses this tool to perform fleet monitoring, node health checks, and alert management via shell commands. - [INDIRECT_PROMPT_INJECTION]: The agent ingests and interprets JSON data returned by the
nvfleetintCLI, which is sourced from a remote API. This introduces a potential surface where compromised or malicious data returned by the backend could attempt to influence the agent's logic. - Ingestion points: CLI output from
nvfleetintcommands (e.g.,overview,node list,alert summary) is processed inSKILL.mdandreferences/cli-contract.md. - Boundary markers: The skill mandates the use of
--output jsonand requires the agent to parse specific backend fields (e.g.,healthStatus,integrityCheck), providing structural constraints on data ingestion. - Capability inventory: The agent has the capability to execute shell commands using the
nvfleetintbinary across all operation scripts. - Sanitization: The
references/cli-contract.mdfile provides instructions to validate the integrity of the JSON response and check for specific error keys (error,api_error) before the data is analyzed.
Audit Metadata