osmo-admin
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the shell tool for read-only operations such as
git diff,git log,grep, andfindto assist in configuration management. The instructions explicitly forbid dangerous or destructive commands includingrm,git reset --hard, andgit checkout --. Execution is strictly scoped to the user-provided configuration root. - [EXTERNAL_DOWNLOADS]: The skill references official documentation hosted on
nvidia.github.io. As these are resources provided by the vendor (NVIDIA), they are considered trusted sources for schema validation and deployment guidelines. - [CREDENTIALS_SAFE]: The skill includes specific rules to prevent the printing of secret payloads. It instructs the agent to refer only to secret names, key names, and reference paths found in
secretRefsmetadata, ensuring sensitive data is not exposed in the agent's output. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided configuration files. While this presents a surface for indirect prompt injection, the skill mitigates this risk through strict instructions to cite specific YAML key paths, perform bounded reads, and refuse requests related to live workflow support or diagnostics that could be used to bypass safety filters.
Audit Metadata