fault-injection-loop
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
sbatchandsqueueto manage distributed jobs on a SLURM cluster. This is standard and necessary for its purpose of benchmarking distributed training workloads. - [EXTERNAL_DOWNLOADS]: The skill references container images from
nvcr.io/nvidia/nemo:26.04. This is a vendor-owned registry and is appropriate for the skill's context. - [CREDENTIALS_UNSAFE]: The skill instructs users to manage sensitive API keys via local, untracked files (
scripts/user.env,LLM_API_KEY_FILE). This is a recommended security practice to prevent accidental credential leakage in code repositories. - [REMOTE_CODE_EXECUTION]: While the skill executes local scripts (
prepare_node_alloc.sh,watch_and_analyze.sh) and interacts with external LLM APIs for log analysis and scoring, these operations are directed at vendor-owned endpoints (integrate.api.nvidia.com) and utilize user-provided local scripts.
Audit Metadata