skills/nvidia/osmo/osmo-user/Gen Agent Trust Hub

osmo-user

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the osmo CLI to perform legitimate operations such as submitting workflows, checking resource availability, and managing credentials. This functionality is the primary purpose of the skill.
  • [EXTERNAL_DOWNLOADS]: The skill fetches workflow examples, documentation, and configuration from the official NVIDIA OSMO GitHub repository. As these originate from the skill's own vendor, they are considered safe resources.
  • [PROMPT_INJECTION]: There is a surface for indirect prompt injection because the skill ingest workflow logs and external YAML templates to diagnose failures or generate new workflows. However, the instructions provide specific procedures and constraints that limit the agent's actions to well-defined troubleshooting and management tasks, which is standard for this use case.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 05:57 AM
Security Audit — agent-trust-hub — osmo-user