skills/nvidia/skills/hsb-ip-def/Gen Agent Trust Hub

hsb-ip-def

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run in scripts/generate_def.py to invoke the local validation script scripts/validate_def.py. This is a controlled internal operation used to verify the integrity of generated configuration files using the environment's Python interpreter.\n- [EXTERNAL_DOWNLOADS]: Technical documentation and references within the skill point to official NVIDIA source repositories on GitHub. These links target well-known and trusted vendor infrastructure for legitimate project documentation.\n- [PROMPT_INJECTION]: The skill processes external SystemVerilog files and configuration profiles which represent an indirect prompt injection surface. This risk is effectively mitigated by specific instructions requiring the agent to obtain explicit user confirmation before any file access or command execution, maintaining a human-in-the-loop security model.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 01:09 PM
Security Audit — agent-trust-hub — hsb-ip-def