skills/nvidia/skills/launching-evals/Gen Agent Trust Hub

launching-evals

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes NVIDIA's official GitHub repositories and container registries (nvcr.io) for software installation and documentation, which are within the trusted vendor scope.
  • [SAFE]: Instructions for handling credentials, such as HF_TOKEN, correctly recommend the use of .env files to avoid hardcoding secrets.
  • [SAFE]: Command execution via 'uv run' and remote access via 'ssh' are strictly mapped to the primary purpose of executing evaluation tasks and retrieving logs.
  • [SAFE]: The skill ingests and processes untrusted data (evaluation logs), representing an indirect prompt injection surface. However, this is inherent to the task of log analysis and does not result in elevated privileges or unsafe command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 06:14 AM
Security Audit — agent-trust-hub — launching-evals