migration-ascend-torchnpu-skills
Fail
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends using 'https://bgithub.xyz' as a mirror for cloning GitHub repositories. This domain is flagged as malicious by automated scanners and acts as an unverified third-party proxy. Recommending such services for code acquisition introduces supply chain risks, including potential man-in-the-middle attacks or unauthorized code modifications.
- [COMMAND_EXECUTION]: The environment setup process involves numerous high-privilege administrative commands, including 'sudo', 'docker run --privileged', and the execution of binary driver installers ('*.run'). These commands grant extensive control over the host system and should only be performed using verified official resources.
- [EXTERNAL_DOWNLOADS]: The instructions facilitate the download and installation of various software packages from external sources such as 'download.pytorch.org', 'gitcode.com', and 'ffmpeg.org'. While these domains are often legitimate, the inclusion of suspicious proxy mirrors for GitHub is a security concern.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- Contains 3 malicious URL(s) - DO NOT USE
Audit Metadata