nemo-evaluator-plugin

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides extensive documentation and specific examples for secure secret management, directing users to reference environment variables or platform-managed secrets rather than hardcoding API keys.
  • [SAFE]: The skill demonstrates defensive prompt engineering in its LLM-as-judge examples, including specific instructions for the model to treat input data as untrusted to mitigate indirect prompt injection risks.
  • [EXTERNAL_DOWNLOADS]: The skill references a helper script for installing the Fabric runner which downloads a checksum-verified 'nemo-relay' binary from NVIDIA's official distribution channels.
  • [COMMAND_EXECUTION]: The skill enables developers to execute evaluation tasks, submit remote jobs to the NeMo Platform, and manage evaluation artifacts using the 'nemo evaluator' CLI and associated Python SDK.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 07:09 PM
Security Audit — agent-trust-hub — nemo-evaluator-plugin