The skill bypasses human-in-the-loop controls for infrastructure changes, insecurely handles sensitive API keys, and executes unconstrained network and system operations without declaring required tool permissions.
npx skills add https://github.com/nvidia/skillsThe instructions explicitly provide a mechanism to bypass human confirmation for deployment if the user includes keywords like 'autonomously' or 'non-interactive', which can be exploited to perform unauthorized infrastructure changes. [ensemble: confirmed by 3/3 passes; severity set to the agreed median (ADR-0067).]
If the user's request already asks you to run autonomously (e.g. 'deploy X autonomously', 'run without confirmation', 'non-interactive'), skip the confirmation prompt and proceed straight to Step 5.
The skill handles multiple sensitive API keys (NGC, NVIDIA, HF) and writes them into a generated environment file, which may be logged or persisted in insecure locations.
Validate every credential... before Step 1c copies .env to generated.env
Remote installer fetch-and-run from a known first-party endpoint (downgraded from critical)
https://astral.sh/
Autonomous operation instructions detected — attempts to remove human-in-the-loop controls
autonomous mode
SKILL.md links to "references/alerts.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[`references/alerts.md`](references/alerts.md)
SKILL.md links to "references/base.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[`references/base.md`](references/base.md)
SKILL.md links to "references/lvs-profile.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[`references/lvs-profile.md`](references/lvs-profile.md)
SKILL.md links to "references/search.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[`references/search.md`](references/search.md)
SKILL.md links to "references/warehouse.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[`references/warehouse.md`](references/warehouse.md)
[](https://mondoo.com/ai-agent-security/skills/github/nvidia/skills/vss-deploy-profile)<a href="https://mondoo.com/ai-agent-security/skills/github/nvidia/skills/vss-deploy-profile"><img src="https://mondoo.com/ai-agent-security/api/badge/github/nvidia/skills/vss-deploy-profile.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/nvidia/skills/vss-deploy-profile.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.