nvalchemi-zarr-perf

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for using skip_validation=True within the Dataset class to bypass Pydantic validation for increased throughput.
  • Ingestion points: Data is loaded from Zarr stores (.zarr) via the AtomicDataZarrReader class as described in SKILL.md.
  • Boundary markers: The skip_validation parameter explicitly disables the Pydantic validation boundary that normally checks data integrity during loading.
  • Capability inventory: The pipeline reads raw tensor dictionaries and metadata for use in training or inference datasets and data loaders.
  • Sanitization: The skill contains an explicit security warning: 'Do not use when: the store contents are untrusted or from a third party.'
  • [COMMAND_EXECUTION]: The benchmark workflow uses the uv package manager to run performance tests.
  • Evidence: Shell commands like uv run nvalchemi-io-test roundtrip are provided for performance benchmarking.
  • Context: These commands are standard for developer performance testing of the local I/O pipeline and utilize the project's own benchmarking tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 11:49 PM
Security Audit — agent-trust-hub — nvalchemi-zarr-perf