nemo-fabric-integrate

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the development of agent harnesses that process untrusted external data via the input and request parameters of the run() and invoke() methods.
  • Ingestion points: SKILL.md and references/sdk-api-inventory.md (usage patterns for the run and invoke methods).
  • Boundary markers: No explicit delimiters or instructions for the agent to ignore embedded commands are present in the provided integration examples.
  • Capability inventory: The resulting agent runtimes can have access to the local file system (via add_skill_path) and network services/tools (via add_mcp_server).
  • Sanitization: The integration guide does not describe specific sanitization or validation steps for input data before it is passed to the Fabric runtime.
  • [DYNAMIC_EXECUTION]: The SDK allows for the dynamic loading of executable logic (skills) from file system paths using the add_skill_path method. This enables the runtime to incorporate and execute logic from a directory specified in the configuration at runtime.
  • [EXTERNAL_DOWNLOADS]: The documentation references official NVIDIA GitHub repositories for downloading and installing the NeMo Fabric SDK, adapters, and associated examples. These are recognized as trusted vendor resources.
  • Evidence: https://github.com/NVIDIA/NeMo-Fabric/
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 03:00 AM
Security Audit — agent-trust-hub — nemo-fabric-integrate