rag-eval

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill is an import from the NVIDIA RAG Blueprint, adhering to standard DevOps and AI evaluation practices without malicious intent.
  • [COMMAND_EXECUTION]: The skill guides the user to run evaluate_rag.py using the uv toolchain to perform ingestion and evaluation against a RAG server.
  • [EXTERNAL_DOWNLOADS]: Instructions include the materialization of documents from public links into a local corpus/ directory to facilitate retrieval testing.
  • [CREDENTIALS_UNSAFE]: The skill utilizes the NVIDIA_API_KEY for RAGAS scoring but provides comprehensive security guidance on avoiding shell history exposure and preventing the commitment of secrets to version control.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 01:39 AM
Security Audit — agent-trust-hub — rag-eval