hyperpod-issue-report
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
scripts/hyperpod_issue_report.pyscript downloads a diagnostic utility (eks-log-collector.sh) from the official awslabs GitHub repository. This download is secured using a pinned commit hash and a mandatory SHA256 integrity check within the generated node script. - [REMOTE_CODE_EXECUTION]: The skill performs remote execution by creating a temporary bash script and running it on HyperPod cluster nodes via AWS Systems Manager (SSM) Session Manager. This is the primary mechanism for collecting diagnostic logs from individual compute nodes.
- [COMMAND_EXECUTION]: The bundled Python script executes local shell commands using
subprocess.runto interact withkubectland theawsCLI. These operations are used to gather cluster-wide metadata (e.g., node capacity, pod status, cluster events). The script uses list-based arguments andshlex.quotefor variable interpolation to mitigate command injection risks. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill ingests data from external sources including AWS SageMaker/EKS APIs and
kubectlcommand outputs inscripts/hyperpod_issue_report.py. - Boundary markers: While data is processed, the skill primarily acts as a transport mechanism, uploading raw logs to S3 rather than feeding untrusted log content directly back into the agent's reasoning loop.
- Capability inventory: The skill possesses capabilities for local command execution (
aws,kubectl), remote script execution (via SSM), and network writes (S3 uploads). - Sanitization: The script employs
shlex.quotewhen building shell commands that include user-supplied or cluster-provided identifiers.
Audit Metadata