skills/nvidia/skills/rag-blueprint/Gen Agent Trust Hub

rag-blueprint

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill facilitates the management of NVIDIA RAG Blueprint deployments. It includes commands for hardware detection, container management, and service health monitoring.
  • [COMMAND_EXECUTION]: The skill requires access to a variety of shell tools (Bash, docker, kubectl, helm) to perform its stated purpose of managing infrastructure. These commands are restricted to specific administrative and diagnostic tasks.
  • [EXTERNAL_DOWNLOADS]: The skill references official NVIDIA and Docker documentation and services (e.g., NGC registry, NVIDIA API catalog) for pulling images and performing cloud-based inference. These are trusted vendor resources.
  • [CREDENTIALS_UNSAFE]: The skill handles API keys (NGC_API_KEY) but does so safely by checking for their presence in environment variables or configuration files without exposing the values, or by instructing the user to perform sensitive actions (like docker login) manually.
  • [PROMPT_INJECTION]: No evidence of prompt injection or instructions to bypass safety guardrails was found. The skill includes references for configuring NeMo Guardrails to improve safety.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data exfiltration. Network operations are limited to health checks, API interaction with official NVIDIA endpoints, and standard package/container management.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 07:42 PM
Security Audit — agent-trust-hub — rag-blueprint