fault-injection-loop

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses sbatch and squeue to manage distributed jobs on a SLURM cluster. This is standard and necessary for its purpose of benchmarking distributed training workloads.
  • [EXTERNAL_DOWNLOADS]: The skill references container images from nvcr.io/nvidia/nemo:26.04. This is a vendor-owned registry and is appropriate for the skill's context.
  • [CREDENTIALS_UNSAFE]: The skill instructs users to manage sensitive API keys via local, untracked files (scripts/user.env, LLM_API_KEY_FILE). This is a recommended security practice to prevent accidental credential leakage in code repositories.
  • [REMOTE_CODE_EXECUTION]: While the skill executes local scripts (prepare_node_alloc.sh, watch_and_analyze.sh) and interacts with external LLM APIs for log analysis and scoring, these operations are directed at vendor-owned endpoints (integrate.api.nvidia.com) and utilize user-provided local scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:27 PM
Security Audit — agent-trust-hub — fault-injection-loop