Nemotron CustomizeSAFE
Developer Asset Hub for NVIDIA Nemotron — A one-stop resource for training recipes, usage cookbooks, datasets, and full end-to-end reference examples to build with Nemotron models
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Per-step extracts of upstream library documentation. Load these only after the bundled catalog/run/artifact references have selected a step and an action needs real library API detail.
Lookup
index.toml maps (step_id, intent) → pack file. The Act phase reads this once and dispatches packs to per-stage sub-agents.
Provenance
These packs are not the step catalog. For routing and normal execution, read:
../CATALOG.md../ARTIFACTS.md../COMMANDS.md../PATTERNS.md../HARDWARE.md
Each *.txt file is a snapshot of upstream docs + selected source files from one of:
These packs are curated summaries for agent grounding. They are intentionally short and should point agents back to bundled references first, then to the repo step manifest, config, runner, and active profile TOML for live verification.
441e9a359902OBSERVED · 2026-10-09Install
Commands as the repository documents them. They are shown, not run.
uv run nemotron steps list --json
uv run nemotron steps list --json --category <category>
uv run nemotron steps show <step_id>
uv run nemotron steps run <step_id> -c <config-or-path> --dry-run
uv run nemotron steps run <step_id> -c <config-or-path> --dry-run --batch <profile>
uv run nemotron steps run <step_id> -c <config-or-path> --batch <profile>
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| codex | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: nemotron-customize description: "Plan, configure, and chain repo-native Nemotron customization steps into single-step or multi-step pipelines: curation, translation, SFT/PEFT (AutoModel or Megatron-Bridge), pretraining/CPT, RL alignment (DPO/RLVR/GRPO/RLHF), BYOB/MCQ benchmarks, checkpoint conversion, ModelOpt optimization, env profiles, and evaluation of trained checkpoints or existing/hosted endpoints. Use when a request names a Nemotron step or workflow, or asks to clean, translate, train, fine-tune, align, convert, optimize, evaluate, or compose these into a pipeline. Do NOT use for frontend/dashboard/visualization work, generic ML advice, billing/access, or non-Nemotron coding tasks." version: 0.1.1 license: Apache-2.0 metadata: version: 0.1.1 author: NVIDIA Nemotron Team <[email protected]> tags: - nemotron - customization - training - pipelines --- # nemotron-customize IMPORTANT: Read this file before answering any `nemotron-customize`, Nemotron customization, Curator curation, translation, SFT, PEFT, RL, conversion, optimization, checkpoint or existing/hosted-endpoint evaluation, or multi-step pipeline request. This applies whether the user names one step or asks you to compose several steps into a pipeline. Evaluation requests count even when no training is involved: "evaluate", "benchmark", "smoke test", or "score" an existing/hosted endpoint, an API/model ID, or a deployed model all route to `eval/model_eval`. Read this skill for those too. ## Purpose Turn a model-customization request into a repo-native Nemotron step pipeline. Plan the DAG, validate artifact wiring, and create only the YAML/config files needed to run existing steps. Use this skill only for inspecting, configuring, validating, running, or submitting existing Nemotron steps or multi-step training/customization pipelines. For frontend, dashboard, visualization, generic ML advice, billing/access, or unrelated coding tasks, stop with a short scope note and do not inspect the step catalog or edit files in that turn. ## Prerequisites - A checkout of the Nemotron repo with `src/nemotron/steps/` present; run from the repo root. - `uv` available to invoke `uv run nemotron steps ...`. - For remote execution: an env profile TOML (`NEMOTRON_ENV_FILE` or `env*.toml`) with a section matching the selected step. - For hosted services (translation, hosted eval): the auth environment variable expected by the step (for example `NVIDIA_API_KEY`), exported in the environment — never inlined or committed. - User-provided concrete values (model/checkpoint, data paths, output dir, hardware/GPU count) before any command is presented as runnable. ## Limitations - Does not invent new catalog steps. When no existing step, runner, recipe, CLI, or config can satisfy the request, it names the gap (Explorer mode) instead of fabricating a step. - Produces YAML/config for existing steps; new Python/shell is out of scope except in Explorer mode after the gap is approved. - Not for deployment-only/serving, frontend, dashboards, generic ML advice, or non-Nemotron tasks. - Does not guess concrete values (paths, model IDs, GPU counts, profiles); it asks or returns `Blocked` when they are missing. ## Core Rule Use bundled references first. The `references/` folder is the first decision surface for routing, artifacts, patterns, hardware heuristics, and command shape. Use `src/nemotron/steps/...` only as a live verification/fallback source when you need exact current config fields, manifests, runner imports, or details missing from bundled references. If sources disagree: 1. Checked live repo files win for exact execution. 2. Bundled references win for initial routing and planning. 3. Upstream docs/context packs are used only for exceptional code generation or library API details. ## Before You Begin - Read this `SKILL.md` workflow and the relevant bundled reference before opening repo source files. - Route from `references/CATALOG.md` and `references/ARTIFACTS.md` before any broad repo exploration. Once a route is determined, verify only the selected live step/config/env files needed for the answer. - Do not emit commands with fake paths, placeholder model IDs, guessed task IDs, guessed batch profiles, or default auth variable names presented as facts. Ask for missing concrete values or return a `Blocked` handoff. - Use `references/COMMANDS.md` as the authoritative checklist before finalizing configs or execution commands. - For pipeline requests, plan before editing. Do not create or modify files until the DAG, artifact edges, required inputs, and validation checks are stated and approved. - For one-shot command requests, prefer a complete parameterized command in one response over exploratory prose, but only after required inputs are known. If the user already provides the needed values and asks for only a command, answer with the command first and keep explanation minimal. - Output discipline (keeps responses tight): emit one command block per step, include only flags the step actually defines, and add no speculative or invented flags. Keep narrative to a few lines — the command plus the required safety/profile callouts, not a tutorial. Do not restate reference content the user did not ask for. - Do not spawn subagents for one-shot command lookup. Use the bundled command reference directly; verify only the selected step if needed. ## Safety Keep Bash scoped to repo-safe commands such as `uv run nemotron steps ...`, targeted tests, `git status/diff`, and config validation. Never run environment dumps (`env`, `printenv`, broad `export`) or commands that expose secret values. For remote submissions, destructive changes, or expensive launches, confirm before execution. When inspecting env/config files, avoid printing whole files that may contain secrets. Use targeted reads, report only section names and env-var names, and redact values for fields
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
441e9a359902full audit observations/trust-audit/skill/nvidia-nemo__nemotron-customize.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 441e9a359902 | SAFE | B | 89 | first audit |
Questions
What does the Nemotron Customize skill do?
Developer Asset Hub for NVIDIA Nemotron — A one-stop resource for training recipes, usage cookbooks, datasets, and full end-to-end reference examples to build with Nemotron models
Is Nemotron Customize safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Nemotron Customize access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Nemotron Customize work with?
Its documentation mentions codex. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (441e9a359902), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.