nvfleetint

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs users to obtain binary releases from the official GitHub repository for the NVIDIA Fleet Intelligence Client. These resources are hosted by a well-known service and provided by the official vendor.
  • [COMMAND_EXECUTION]: The skill relies on the execution of the nvfleetint command-line tool. The agent uses this tool to perform fleet monitoring, node health checks, and alert management via shell commands.
  • [INDIRECT_PROMPT_INJECTION]: The agent ingests and interprets JSON data returned by the nvfleetint CLI, which is sourced from a remote API. This introduces a potential surface where compromised or malicious data returned by the backend could attempt to influence the agent's logic.
  • Ingestion points: CLI output from nvfleetint commands (e.g., overview, node list, alert summary) is processed in SKILL.md and references/cli-contract.md.
  • Boundary markers: The skill mandates the use of --output json and requires the agent to parse specific backend fields (e.g., healthStatus, integrityCheck), providing structural constraints on data ingestion.
  • Capability inventory: The agent has the capability to execute shell commands using the nvfleetint binary across all operation scripts.
  • Sanitization: The references/cli-contract.md file provides instructions to validate the integrity of the JSON response and check for specific error keys (error, api_error) before the data is analyzed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 07:02 AM
Security Audit — agent-trust-hub — nvfleetint