nvflare-convert-lightning
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface because it processes untrusted user-supplied code and data formats alongside tool capabilities that execute scripts.
- Ingestion points: Ingests user-supplied PyTorch Lightning code scripts, model descriptors, and external file locations (e.g., CSV tabular data configurations loaded by the DataModules).
- Boundary markers: Lacks robust prompt boundary delimiters or isolated parsing blocks to sanitize embedded instructions from within source text files or dataset configurations.
- Capability inventory: Possesses capabilities to invoke local script execution (
python job.py) and trigger the NVFLARE simulator CLI during the validation workflow. - Sanitization: Relies entirely on static file structure checks and host environment permissions without active input sanitization or sandboxing of the generated execution parameters.
Audit Metadata