nvca-values-customization
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external configuration data from
.envfiles and YAML override files, which are interpolated into Helm values and shell commands. - Ingestion points: Environment variables in
.envand override files passed to theadditional_valuesparameter. - Boundary markers: None explicitly defined in the documentation.
- Capability inventory: The skill utilizes shell commands such as
make,helm,git, andyqto manage deployments. - Sanitization: The instructions recommend careful use of
yqfor nested keys and quoting, and utilize dummy API keys for default configurations to mitigate accidental credential exposure. - [SAFE]: The skill refers exclusively to resources within the vendor's own infrastructure (Nvidia) and provides clear guidance on avoiding the commitment of secrets or real credentials, which aligns with secure development practices.
Audit Metadata