skills/nvidia/skills/nemo-retriever/Gen Agent Trust Hub

nemo-retriever

Pass

Audited by Gen Agent Trust Hub on May 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the NeMo Retriever source code from the official NVIDIA GitHub repository during the installation phase, which is an expected and safe operation for this vendor-provided skill.
  • [COMMAND_EXECUTION]: The workflow requires executing the retriever CLI for document ingestion and vector search, along with utility scripts for keyword matching and fast-path file processing.
  • [COMMAND_EXECUTION]: The skill provides instructions for installing host-level dependencies such as libreoffice and ffmpeg via sudo to support document conversion and multimedia processing.
  • [SAFE]: Instructions maintain strict operational limits, including a maximum of two tool calls per query turn, to ensure performance and prevent excessive resource consumption.
Audit Metadata
Risk Level
SAFE
Analyzed
May 30, 2026, 01:38 AM
Security Audit — agent-trust-hub — nemo-retriever