nvrx-attr

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an automated LLM judge to evaluate failure attributions, which ingests raw log data from the workload execution environment.
  • Ingestion points: The script scripts/score_attribution.py reads raw job logs and incorporates them, along with external analyzer outputs, into its evaluation prompt.
  • Boundary markers: The LLM prompt uses structured Markdown headers (e.g., '## Raw job log') to separate ground-truth data from the raw log content.
  • Capability inventory: The skill bundle includes shell scripts with permissions to submit SLURM jobs, monitor job status, and interact with the local filesystem.
  • Sanitization: While the scripts filter out specific diagnostic markers from the logs to prevent evaluation bias, they do not comprehensively sanitize the log content for potential adversarial instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:27 PM
Security Audit — agent-trust-hub — nvrx-attr