vast-cli
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructional shell command snippets for interacting with the
vastaiservice. All commands are standard for the tool's intended use case and do not contain hidden or malicious payloads. - [SAFE]: Credential management instructions involve standard local file paths for API keys and SSH keys. There is no evidence of credential harvesting or data exfiltration.
- [SAFE]: The SSH connection logic correctly handles the dynamic nature of cloud instance host/port rotation using standard OpenSSH flags. While these flags skip host key verification, this is the accepted operational pattern for the target service.
- [SAFE]: Upstream references in the documentation point to legitimate repositories owned by the verified vendor, ensuring the integrity of the skill's source material.
Audit Metadata