tao-run-automl-deft-pipeline

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a workflow orchestrator, delegating complex operations to other established skills (tao-run-automl and tao-run-deft-aoi). It does not implement its own execution logic that would bypass security boundaries.
  • [COMMAND_EXECUTION]: Shell commands are used for routine file operations such as copying configuration files and updating state JSONs. These commands are executed within the defined workspace and do not involve unauthorized privilege escalation or persistence mechanisms.
  • [EXTERNAL_DOWNLOADS]: References to container images from nvcr.io (NVIDIA Container Registry) and configuration from official NVIDIA repositories are documented. These are trusted sources consistent with the skill's purpose as an NVIDIA-authored tool.
  • [PROMPT_INJECTION]: No evidence of malicious instructions or attempts to bypass agent safety guidelines was found. The instructions focus on routing policies and workflow sequencing.
  • [DATA_EXFILTRATION]: No network operations to non-whitelisted or suspicious domains were detected. File access is limited to the local workspace for training data and configuration management.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 02:38 PM
Security Audit — agent-trust-hub — tao-run-automl-deft-pipeline