skills/nvidia/megatron-lm/mcore-cicd/Gen Agent Trust Hub

mcore-cicd

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze external data from CI logs and GitHub PR metadata, creating a vulnerability surface where malicious content in those sources could influence agent behavior.
  • Ingestion points: PR metadata (title, labels, author) via gh pr view, PR diffs via gh pr diff, and log artifacts downloaded from GitHub Actions via gh run download.
  • Boundary markers: The instructions do not define clear delimiters or provide instructions for the agent to ignore embedded commands within the processed log files.
  • Capability inventory: The skill uses gh CLI for repository interaction, local shell tools (grep, sed, wc) for log processing, and a Python script for remote repository interaction.
  • Sanitization: There are no documented steps for sanitizing or escaping the content of the logs before processing.
  • [COMMAND_EXECUTION]: The skill provides instructions for triggering an internal CI pipeline using tools/trigger_internal_ci.py, which performs a force-push to a remote GitLab repository. While the skill includes a prominent warning about the destructive nature of this command and mandates a --dry-run preflight check, it remains a high-risk operation that requires careful oversight.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:19 PM
Security Audit — agent-trust-hub — mcore-cicd