nvcf-self-managed-cli

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to perform infrastructure operations, including cluster registration, deployment, and teardown using nvcf-cli, kubectl, and helm. It includes robust safety rules requiring explicit human confirmation for destructive operations like cluster deletion, task deletion, and persistent data removal.
  • [EXTERNAL_DOWNLOADS]: The skill fetches official Kubernetes Gateway API manifests from the Kubernetes-sigs GitHub repository and downloads the Envoy Gateway Helm chart from Docker Hub. These are well-known, established sources for cloud-native infrastructure components.
  • [INDIRECT_PROMPT_INJECTION]: The agent processes output from the nvcf-cli tool and Kubernetes logs, which constitutes an indirect injection surface if external data (such as task descriptions or container logs) contains malicious instructions.
  • Ingestion points: command output from nvcf-cli self-hosted status, nvcf-cli task events, and kubectl logs (documented in prompts/diagnose-failed-install.md).
  • Boundary markers: The skill encourages the use of the --json flag for structured parsing, which helps mitigate schema confusion, though it does not specify delimiters for raw text logs.
  • Capability inventory: The skill uses the Bash tool across multiple scripts to manage cluster state and containerized workloads.
  • Sanitization: Instructions explicitly require the agent to scan command outputs (specifically stderrTail) for secrets and credentials before surfacing information to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:27 PM
Security Audit — agent-trust-hub — nvcf-self-managed-cli