osmo-admin
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill enforces a 'First Action Gate' that requires an explicit configuration root from the user, preventing unauthorized or accidental workspace discovery.
- [SAFE]: Core rules 9 and 10 explicitly forbid the execution of live administration commands (e.g.,
osmo config,kubectl) or cluster mutation commands, ensuring the agent remains in a local, read-only/diff-only state. - [SAFE]: Rule 11 prohibits destructive shell commands such as
rm -rf,git clean, orgit reset, protecting the user's filesystem from accidental or malicious deletion. - [SAFE]: Rule 12 explicitly prevents the printing or handling of secret payloads, directing the agent to only refer to secret names or keys.
- [EXTERNAL_DOWNLOADS]: Reference documentation includes links to
nvidia.github.io. Since these are official resources belonging to the skill's author (NVIDIA), they are documented as trusted and do not pose a security risk.
Audit Metadata