nemo-mbridge-perf-cuda-graphs

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard technical documentation and configuration guidance for NVIDIA's Megatron Bridge performance features. Analysis across all 10 threat categories confirms:
  • No Prompt Injection: Instructions focus on technical configuration and do not attempt to override agent safety or identity.
  • No Data Exfiltration: The skill does not access sensitive files (~/.ssh, ~/.aws) or attempt unauthorized network transfers. References to local config paths (cfg.model) are standard within the Megatron framework.
  • No Obfuscation: All content is human-readable markdown and standard code blocks (Python/Bash) with no hidden Unicode, Base64 commands, or homoglyphs.
  • Safe Dependencies: Uses standard tools like uv run and python targeting internal repository scripts (scripts/performance/run_script.py). No untrusted external packages or remote code execution via pipes (curl|bash) are present.
  • Safe Command Execution: Commands provided are illustrative benchmarks for performance tuning (run_script.py) and do not involve privilege escalation (sudo) or persistence mechanisms.
  • Metadata and Verification: The skill contains valid metadata, benchmark data, and a digital signature (skill.oms.sig) from NVIDIA, ensuring authenticity and integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 12:21 PM
Security Audit — agent-trust-hub — nemo-mbridge-perf-cuda-graphs