nemo-evaluator-plugin
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides extensive documentation and specific examples for secure secret management, directing users to reference environment variables or platform-managed secrets rather than hardcoding API keys.
- [SAFE]: The skill demonstrates defensive prompt engineering in its LLM-as-judge examples, including specific instructions for the model to treat input data as untrusted to mitigate indirect prompt injection risks.
- [EXTERNAL_DOWNLOADS]: The skill references a helper script for installing the Fabric runner which downloads a checksum-verified 'nemo-relay' binary from NVIDIA's official distribution channels.
- [COMMAND_EXECUTION]: The skill enables developers to execute evaluation tasks, submit remote jobs to the NeMo Platform, and manage evaluation artifacts using the 'nemo evaluator' CLI and associated Python SDK.
Audit Metadata