skills/nvidia/nurec-skills/nre/Gen Agent Trust Hub

nre

Warn

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCE
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill implements a mechanism to extract Python gRPC stubs directly from a Docker image and load them into the host Python environment via path manipulation in thin_client.py. It also performs runtime patching of Bazel build configuration files using sed to bypass user-level restrictions during training workflows.
  • [COMMAND_EXECUTION]: Orchestration scripts rely on docker run with high privileges, including the use of --privileged, --net=host, and direct hardware access via --gpus all. It also executes complex build processes through bazel run to convert sensor data and train neural models.
  • [PRIVILEGE_ESCALATION]: Setup templates (tools.yaml) utilize sudo for installing system-level dependencies such as Docker and the NVIDIA Container Toolkit. Documentation also guides users to use sudo chown to manage files produced by containerized processes that run as root.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data including NCore shards and USDZ scenes which can be loaded from arbitrary URLs. This data is ingested into high-capability execution environments, creating a significant vulnerability surface where malicious inputs could influence the behavior of the AI agent or its underlying tools.
  • [REMOTE_CODE_EXECUTION]: Automated installation steps in tools.yaml execute remote scripts from well-known domains using shell piping (e.g., curl | sh). While the domains (get.docker.com, helm.sh) are legitimate, the pattern of executing unverified remote code is a high-risk capability.
  • [EXTERNAL_DOWNLOADS]: The skill pulls numerous binary tools and containers from external registries (NVIDIA NGC, HuggingFace, GitHub). While these are trusted vendor sources, the complexity of the automated supply chain increases the risk of resource poisoning.
  • [PERSISTENCE]: Installation scripts modify the user's ~/.bashrc to permanently add binary paths for tools like Go to the system PATH, ensuring they remain available across all future sessions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 4, 2026, 02:25 PM
Security Audit — agent-trust-hub — nre