nim-operator-install

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Helm charts and user-provided configuration values which are subsequently used in high-privilege cluster management commands.
  • Ingestion points: User-supplied parameters (version, namespace, and Helm values) and remote Helm repository data.
  • Boundary markers: Instructions explicitly mandate asking for confirmation and summarizing impact before executing any mutating command.
  • Capability inventory: Use of helm upgrade --install, kubectl apply, kubectl patch, and kubectl delete for cluster resource management in SKILL.md and scripts/validate-nim-operator-install.sh.
  • Sanitization: No explicit programmatic validation or sanitization is implemented for user-provided Helm values within the provided scripts.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of cluster-management commands using kubectl and helm, and includes instructions for remote execution over SSH.
  • [EXTERNAL_DOWNLOADS]: The skill fetches Helm charts and repository updates from the official NVIDIA Helm repository at https://helm.ngc.nvidia.com/nvidia.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:30 PM
Security Audit — agent-trust-hub — nim-operator-install