hyperpod-issue-report

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The scripts/hyperpod_issue_report.py script downloads a diagnostic utility (eks-log-collector.sh) from the official awslabs GitHub repository. This download is secured using a pinned commit hash and a mandatory SHA256 integrity check within the generated node script.
  • [REMOTE_CODE_EXECUTION]: The skill performs remote execution by creating a temporary bash script and running it on HyperPod cluster nodes via AWS Systems Manager (SSM) Session Manager. This is the primary mechanism for collecting diagnostic logs from individual compute nodes.
  • [COMMAND_EXECUTION]: The bundled Python script executes local shell commands using subprocess.run to interact with kubectl and the aws CLI. These operations are used to gather cluster-wide metadata (e.g., node capacity, pod status, cluster events). The script uses list-based arguments and shlex.quote for variable interpolation to mitigate command injection risks.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill ingests data from external sources including AWS SageMaker/EKS APIs and kubectl command outputs in scripts/hyperpod_issue_report.py.
  • Boundary markers: While data is processed, the skill primarily acts as a transport mechanism, uploading raw logs to S3 rather than feeding untrusted log content directly back into the agent's reasoning loop.
  • Capability inventory: The skill possesses capabilities for local command execution (aws, kubectl), remote script execution (via SSM), and network writes (S3 uploads).
  • Sanitization: The script employs shlex.quote when building shell commands that include user-supplied or cluster-provided identifiers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:58 PM
Security Audit — agent-trust-hub — hyperpod-issue-report