skills/nvidia/nvcf/nvca-chart-release/Gen Agent Trust Hub

nvca-chart-release

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes shell commands to perform build and validation tasks using make, helm, yq, and docker. These commands target the local filesystem and are standard for the described DevOps workflow.
  • [DATA_EXPOSURE]: The instructions explicitly warn the user not to commit service keys, kubeconfigs, or other secrets, which aligns with security best practices for repository management.
  • [REMOTE_CODE_EXECUTION]: No remote code execution or external script downloads were detected. All scripts and tools referenced (e.g., tools/ci/validate-helm-chart) are local to the monorepo context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 11:49 PM
Security Audit — agent-trust-hub — nvca-chart-release