deploy
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands to manage Docker containers and verify system state, including use of sudo for administrative tasks such as kernel tuning and driver management.
- [EXTERNAL_DOWNLOADS]: Downloads the NGC CLI and GPG keys from official NVIDIA repositories (nvidia.com and nvidia.github.io).
- [REMOTE_CODE_EXECUTION]: Automated alerts regarding piped curl commands were analyzed and found to be standard JSON formatting checks on local service endpoints (localhost) using python3 -m json.tool.
- [CREDENTIALS_UNSAFE]: Appropriately manages API keys (NGC, NVIDIA, and Hugging Face tokens) by instructing users to use environment variables instead of hardcoding them.
Audit Metadata