nvidia-kaggle-skill
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes the official
kaggleCLI usingsubprocess.runin scripts such assubmission_quota.pyandupload_dataset.py. These calls use the secure list-based argument format (preventing shell injection), and input parameters like competition slugs are validated against regular expressions defined inruntime.py. - [EXTERNAL_DOWNLOADS]: The skill facilitates the retrieval of competition data, kernel source code, and dataset files exclusively from Kaggle's official domains (
kaggle.com,api.kaggle.com) using standard tools. - [DATA_EXFILTRATION]: The skill manages the
KAGGLE_API_TOKENsecret appropriately, with explicit instructions inSKILL.mdand code checks ensuring the token is never logged, printed, or echoed. - [SAFE]: Robust sanitization logic is implemented to handle untrusted data from Kaggle. This includes
html_to_markdowninruntime.pyto strip potentially malicious HTML andsanitize_cli_outputinupload_dataset.pyto strip ANSI escape sequences and control characters, preventing terminal manipulation or prompt injection from reflected external content.
Audit Metadata