nemo-retriever-mcp

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and retrieval of documents using the ingest_documents and query tools, which creates a surface for indirect prompt injection from external data sources.
  • Ingestion points: The ingest_documents tool referenced in SKILL.md allows the agent to add documents to the retriever.
  • Boundary markers: The instructions recommend grounding responses in "evidence hits" and preserving identifiers, but do not provide explicit instructions for using delimiters to isolate untrusted content.
  • Capability inventory: The skill instructions focus on retrieval and ingestion via MCP tools; no shell execution, file system modification, or network capabilities are present in the skill files.
  • Sanitization: There are no explicit instructions for sanitizing or escaping the content retrieved from documents before it is processed by the model.
  • [NO_CODE]: The skill consists entirely of markdown instructions and configuration metadata. There are no scripts (e.g., Python, JavaScript, Shell) or binaries included in the distribution.
  • [SAFE]: The skill is authored by the official vendor (NVIDIA) and points to trusted vendor documentation at docs.nvidia.com. No obfuscation, credential exposure, or persistence mechanisms were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:12 PM
Security Audit — agent-trust-hub — nemo-retriever-mcp