nvca-values-customization

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external configuration data from .env files and YAML override files, which are interpolated into Helm values and shell commands.
  • Ingestion points: Environment variables in .env and override files passed to the additional_values parameter.
  • Boundary markers: None explicitly defined in the documentation.
  • Capability inventory: The skill utilizes shell commands such as make, helm, git, and yq to manage deployments.
  • Sanitization: The instructions recommend careful use of yq for nested keys and quoting, and utilize dummy API keys for default configurations to mitigate accidental credential exposure.
  • [SAFE]: The skill refers exclusively to resources within the vendor's own infrastructure (Nvidia) and provides clear guidance on avoiding the commitment of secrets or real credentials, which aligns with secure development practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:26 PM
Security Audit — agent-trust-hub — nvca-values-customization