skills/nvidia/skills/paidf-anomalygen/Gen Agent Trust Hub

paidf-anomalygen

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data through ingestion points such as the defect_spec.jsonl file and the dataset_dir directory. This content is interpolated into internal logic to define anomaly types and spatial dependencies. The skill lacks explicit boundary markers or sanitization to prevent adversarial instructions within user-controlled fields like roi_prompt_defect_location. The agent context maintains high capabilities, including file system writes and subprocess execution of training and generation scripts.- [COMMAND_EXECUTION]: The pipeline is managed through the execution of several shell scripts and Python modules, including launch_training.sh for Phase 1, run_sdg.sh for Phase 3, and run_eval.sh for Phase 4. These scripts handle model training, synthetic image generation, and quality evaluation.- [EXTERNAL_DOWNLOADS]: The skill downloads approximately 140 GB of model weights and datasets from well-known services and vendor-owned repositories. Targets include official Hugging Face repositories for Cosmos models and the abin24/Magnetic-tile-defect-datasets repository on GitHub.- [PRIVILEGE_ESCALATION]: The documentation includes instructions for users to use sudo chown or sudo chmod 777 on host directories to address permission issues arising from the container's use of a specific internal UID (10000).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 04:17 AM
Security Audit — agent-trust-hub — paidf-anomalygen