nre
Warn
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCE
Full Analysis
- [DYNAMIC_EXECUTION]: The skill implements a mechanism to extract Python gRPC stubs directly from a Docker image and load them into the host Python environment via path manipulation in
thin_client.py. It also performs runtime patching of Bazel build configuration files usingsedto bypass user-level restrictions during training workflows. - [COMMAND_EXECUTION]: Orchestration scripts rely on
docker runwith high privileges, including the use of--privileged,--net=host, and direct hardware access via--gpus all. It also executes complex build processes throughbazel runto convert sensor data and train neural models. - [PRIVILEGE_ESCALATION]: Setup templates (
tools.yaml) utilizesudofor installing system-level dependencies such as Docker and the NVIDIA Container Toolkit. Documentation also guides users to usesudo chownto manage files produced by containerized processes that run as root. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data including NCore shards and USDZ scenes which can be loaded from arbitrary URLs. This data is ingested into high-capability execution environments, creating a significant vulnerability surface where malicious inputs could influence the behavior of the AI agent or its underlying tools.
- [REMOTE_CODE_EXECUTION]: Automated installation steps in
tools.yamlexecute remote scripts from well-known domains using shell piping (e.g.,curl | sh). While the domains (get.docker.com, helm.sh) are legitimate, the pattern of executing unverified remote code is a high-risk capability. - [EXTERNAL_DOWNLOADS]: The skill pulls numerous binary tools and containers from external registries (NVIDIA NGC, HuggingFace, GitHub). While these are trusted vendor sources, the complexity of the automated supply chain increases the risk of resource poisoning.
- [PERSISTENCE]: Installation scripts modify the user's
~/.bashrcto permanently add binary paths for tools like Go to the system PATH, ensuring they remain available across all future sessions.
Audit Metadata