nvflare-diagnose-job

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes external log files, tracebacks, and console outputs that can contain attacker-influenced or malicious text.
  • Ingestion points: Untrusted log lines, tracebacks, and error text are ingested through commands like nvflare job logs or local file inspection as described in SKILL.md and references/evidence-collection.md.
  • Boundary markers: Present. The skill defines a strict "Log Content Trust Boundary" in SKILL.md and references/evidence-collection.md, explicitly instructing the agent to treat log text as unverified evidence, ignore embedded directives, and flag malicious patterns as SUSPICIOUS_LOG_CONTENT.
  • Capability inventory: The skill utilizes specific read-only commands (nvflare job meta/logs/stats/download, nvflare system status, nvflare agent inspect source). It explicitly forbids modifying configurations, mutating state, or running unbounded scans.
  • Sanitization: Present. The skill mitigates risks by requiring the agent to strictly map log evidence to a rigid failure-pattern catalog (references/failure-patterns.md) instead of interpreting free-text instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:10 PM
Security Audit — agent-trust-hub — nvflare-diagnose-job