nvidia-skill-finder
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches configuration and catalog data from official NVIDIA GitHub repositories and their build platform. These resources are provided by the skill's author for capability discovery and are categorized as trusted resources.\n- [COMMAND_EXECUTION]: Instructs the agent to use CLI tools to list and install skills from the official NVIDIA catalog. The skill explicitly requires user consent before any installation commands are executed.\n- [PROMPT_INJECTION]: The skill processes user queries to identify relevant capabilities within the NVIDIA ecosystem. The analysis identified the following surface vulnerability assessment:\n
- Ingestion points: User natural language requests related to NVIDIA products or AI tasks (SKILL.md).\n
- Boundary markers: Instructions explicitly tell the agent to match requests against stable taxonomy categories and verified catalog entries before recommending action (SKILL.md, references/taxonomy-routing.md).\n
- Capability inventory: Execution of shell commands and network lookups to official catalogs (SKILL.md).\n
- Sanitization: The discovery workflow uses ordered confidence rules and matches against a pre-defined taxonomy to ensure relevant and safe routing.
Audit Metadata