nvcf-self-managed-cli
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool to perform infrastructure operations, including cluster registration, deployment, and teardown using nvcf-cli, kubectl, and helm. It includes robust safety rules requiring explicit human confirmation for destructive operations like cluster deletion, task deletion, and persistent data removal.
- [EXTERNAL_DOWNLOADS]: The skill fetches official Kubernetes Gateway API manifests from the Kubernetes-sigs GitHub repository and downloads the Envoy Gateway Helm chart from Docker Hub. These are well-known, established sources for cloud-native infrastructure components.
- [INDIRECT_PROMPT_INJECTION]: The agent processes output from the nvcf-cli tool and Kubernetes logs, which constitutes an indirect injection surface if external data (such as task descriptions or container logs) contains malicious instructions.
- Ingestion points: command output from
nvcf-cli self-hosted status,nvcf-cli task events, andkubectl logs(documented in prompts/diagnose-failed-install.md). - Boundary markers: The skill encourages the use of the
--jsonflag for structured parsing, which helps mitigate schema confusion, though it does not specify delimiters for raw text logs. - Capability inventory: The skill uses the Bash tool across multiple scripts to manage cluster state and containerized workloads.
- Sanitization: Instructions explicitly require the agent to scan command outputs (specifically
stderrTail) for secrets and credentials before surfacing information to the user.
Audit Metadata