nemo-retriever
Pass
Audited by Gen Agent Trust Hub on May 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the NeMo Retriever source code from the official NVIDIA GitHub repository during the installation phase, which is an expected and safe operation for this vendor-provided skill.
- [COMMAND_EXECUTION]: The workflow requires executing the retriever CLI for document ingestion and vector search, along with utility scripts for keyword matching and fast-path file processing.
- [COMMAND_EXECUTION]: The skill provides instructions for installing host-level dependencies such as libreoffice and ffmpeg via sudo to support document conversion and multimedia processing.
- [SAFE]: Instructions maintain strict operational limits, including a maximum of two tool calls per query turn, to ensure performance and prevent excessive resource consumption.
Audit Metadata