nemo-fabric-build-adapter
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill architecture is designed to ingest and process external requests through the
AgentRunRequestobject in theinvokeandinvoke_openai_streammethods. This creates a potential surface for indirect prompt injection where malicious instructions within user data could attempt to influence the agent's behavior. - Ingestion points:
AgentRunRequest.inputis processed by the adapter implementation inSKILL.md. - Boundary markers: The skill suggests using typed schemas and validating untrusted values to mitigate risks.
- Capability inventory: The adapter implementation enables execution of target workflows (e.g.,
self.target.run(request.input)). - Sanitization: The instructions emphasize that adapters should not log arbitrary user input and should validate incoming values against published JSON schemas.
- [EXTERNAL_DOWNLOADS]: The instructions reference and link to official documentation, integration examples, and JSON schemas hosted on NVIDIA's official GitHub organization. These are recognized as trusted vendor resources.
- [COMMAND_EXECUTION]: The skill provides templates and guidance for implementing adapter methods that execute target-native logic or workflows based on input configurations. This is a primary function of the adapter role and is documented with appropriate state isolation and error handling practices.
Audit Metadata