vast-instance

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the PyTorch library from a specific, official URL (https://download.pytorch.org/whl/cu121). This is a well-known and trusted source for pre-built machine learning binaries.
  • [SAFE]: The skill provides instructions for managing Hugging Face tokens that align with security best practices, such as clearing local caches (rm -f ~/.cache/huggingface/token) and using environment variables rather than hardcoding credentials on disk.
  • [SAFE]: The shell commands provided for searching vast.ai offers and performing file integrity checks (md5sum) are standard administrative operations for GPU instance management.
  • [SAFE]: The external source repository (github.com/a-canary/vast-warmpool) is a vendor-owned resource for this skill and is documented neutrally.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 01:39 AM
Security Audit — agent-trust-hub — vast-instance