nemo-retriever-mcp
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and retrieval of documents using the
ingest_documentsandquerytools, which creates a surface for indirect prompt injection from external data sources. - Ingestion points: The
ingest_documentstool referenced inSKILL.mdallows the agent to add documents to the retriever. - Boundary markers: The instructions recommend grounding responses in "evidence hits" and preserving identifiers, but do not provide explicit instructions for using delimiters to isolate untrusted content.
- Capability inventory: The skill instructions focus on retrieval and ingestion via MCP tools; no shell execution, file system modification, or network capabilities are present in the skill files.
- Sanitization: There are no explicit instructions for sanitizing or escaping the content retrieved from documents before it is processed by the model.
- [NO_CODE]: The skill consists entirely of markdown instructions and configuration metadata. There are no scripts (e.g., Python, JavaScript, Shell) or binaries included in the distribution.
- [SAFE]: The skill is authored by the official vendor (NVIDIA) and points to trusted vendor documentation at
docs.nvidia.com. No obfuscation, credential exposure, or persistence mechanisms were detected.
Audit Metadata