skills/nvidia/skills/nvflare-autofl/Gen Agent Trust Hub

nvflare-autofl

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/run_job_campaign.py uses subprocess.Popen to launch local simulation environments and benchmark job.py execution. This process execution relies on strict token mapping, explicit command line validation via shlex, and explicitly bans shell invocation (shell=False).
  • [SAFE]: All components and libraries are standard utilities provided directly by the vendor (NVIDIA FLARE team) to support local execution profiles, simulation rollbacks, and isolated workspace testing without arbitrary network modifications or privilege escalation vectors.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:01 PM
Security Audit — agent-trust-hub — nvflare-autofl