nvflare-diagnose-job
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes external log files, tracebacks, and console outputs that can contain attacker-influenced or malicious text.
- Ingestion points: Untrusted log lines, tracebacks, and error text are ingested through commands like
nvflare job logsor local file inspection as described inSKILL.mdandreferences/evidence-collection.md. - Boundary markers: Present. The skill defines a strict "Log Content Trust Boundary" in
SKILL.mdandreferences/evidence-collection.md, explicitly instructing the agent to treat log text as unverified evidence, ignore embedded directives, and flag malicious patterns asSUSPICIOUS_LOG_CONTENT. - Capability inventory: The skill utilizes specific read-only commands (
nvflare job meta/logs/stats/download,nvflare system status,nvflare agent inspect source). It explicitly forbids modifying configurations, mutating state, or running unbounded scans. - Sanitization: Present. The skill mitigates risks by requiring the agent to strictly map log evidence to a rigid failure-pattern catalog (
references/failure-patterns.md) instead of interpreting free-text instructions.
Audit Metadata