nightly-sync
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
git,gh(GitHub CLI), anddockerto perform synchronization and CI monitoring tasks. These tools are used to manage the repository and interact with the development environment. - [EXTERNAL_DOWNLOADS]: The skill performs
pip install uv==0.7.2and pulls a specific Docker imagenvcr.io/nvidia/pytorch:26.02-py3from NVIDIA's container registry. These resources are owned by the vendor and are necessary for the synchronization workflow. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process external data including git diffs, commit logs, and CI job logs to identify failures and resolve conflicts.
- Ingestion points:
SKILL.mddefines workflows that ingest git history and CI logs. - Boundary markers: No specific boundary markers are defined for this external content.
- Capability inventory: The agent has access to
git,gh,docker, and Python formatting tools (black,isort,pylint). - Sanitization: No explicit sanitization or filtering is applied to the ingested logs or code before processing.
- [DYNAMIC_EXECUTION]: The skill provides bash templates for the agent to execute for pre-push checks and CI monitoring. These templates are documented as part of the core workflow and do not involve executing untrusted or dynamically assembled code outside of the controlled environment.
Audit Metadata