nvflare-autofl
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/run_job_campaign.pyusessubprocess.Popento launch local simulation environments and benchmarkjob.pyexecution. This process execution relies on strict token mapping, explicit command line validation viashlex, and explicitly bans shell invocation (shell=False). - [SAFE]: All components and libraries are standard utilities provided directly by the vendor (NVIDIA FLARE team) to support local execution profiles, simulation rollbacks, and isolated workspace testing without arbitrary network modifications or privilege escalation vectors.
Audit Metadata