nvrx-attr
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements an automated LLM judge to evaluate failure attributions, which ingests raw log data from the workload execution environment.
- Ingestion points: The script
scripts/score_attribution.pyreads raw job logs and incorporates them, along with external analyzer outputs, into its evaluation prompt. - Boundary markers: The LLM prompt uses structured Markdown headers (e.g., '## Raw job log') to separate ground-truth data from the raw log content.
- Capability inventory: The skill bundle includes shell scripts with permissions to submit SLURM jobs, monitor job status, and interact with the local filesystem.
- Sanitization: While the scripts filter out specific diagnostic markers from the logs to prevent evaluation bias, they do not comprehensively sanitize the log content for potential adversarial instructions.
Audit Metadata