nemo-fabric-build-adapter

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill architecture is designed to ingest and process external requests through the AgentRunRequest object in the invoke and invoke_openai_stream methods. This creates a potential surface for indirect prompt injection where malicious instructions within user data could attempt to influence the agent's behavior.
  • Ingestion points: AgentRunRequest.input is processed by the adapter implementation in SKILL.md.
  • Boundary markers: The skill suggests using typed schemas and validating untrusted values to mitigate risks.
  • Capability inventory: The adapter implementation enables execution of target workflows (e.g., self.target.run(request.input)).
  • Sanitization: The instructions emphasize that adapters should not log arbitrary user input and should validate incoming values against published JSON schemas.
  • [EXTERNAL_DOWNLOADS]: The instructions reference and link to official documentation, integration examples, and JSON schemas hosted on NVIDIA's official GitHub organization. These are recognized as trusted vendor resources.
  • [COMMAND_EXECUTION]: The skill provides templates and guidance for implementing adapter methods that execute target-native logic or workflows based on input configurations. This is a primary function of the adapter role and is documented with appropriate state isolation and error handling practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 03:01 AM
Security Audit — agent-trust-hub — nemo-fabric-build-adapter