nvidia-skill-finder

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches the NVIDIA skills catalog from official, well-known sources including github.com/NVIDIA/skills, build.nvidia.com, and raw.githubusercontent.com/NVIDIA/skills. These are verified vendor resources.
  • [COMMAND_EXECUTION]: Provides instructions for users to run npx skills add, which is the standard management tool for this platform. The instructions explicitly mandate that the agent must never execute installation commands without express user approval.
  • [PROMPT_INJECTION]: Contains instructions for implicit invocation (capability detection), but includes strong 'When Not to Use' constraints to prevent the agent from hijacking generic non-NVIDIA tasks (like generic web routing or CSS optimization).
  • [SAFE]: The skill includes a valid skill.oms.sig signature bundle, indicating it has been cryptographically signed by NVIDIA for integrity verification.
  • [SAFE]: Evaluation data and benchmarks indicate the skill has undergone security testing for secret leakage and unauthorized access with a 100% pass rate.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 07:37 PM
Security Audit — agent-trust-hub — nvidia-skill-finder