hyperpod-slurm-debugger
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed with a strictly read-only constraint, explicitly prohibiting state-mutating commands. Diagnostics are performed via bundled scripts using authenticated AWS CLI calls, ensuring no unauthorized changes are made to the cluster.
- [SAFE]: The
slurm-diagnose.shscript implements rigorous validation for all parameters (region, cluster name, node names, instance IDs) using specific regular expression patterns before they are used in shell commands, mitigating local injection risks. - [SAFE]: Interaction with cluster nodes via AWS Systems Manager (SSM) utilizes a secure wrapper that Base64-encodes the diagnostic payload and uses
jq @shto safely quote environment variables, preventing remote command injection on the target instances. - [SAFE]: The script includes a sanitization helper that strips ANSI escape sequences and control characters from server-derived data before outputting to the user's terminal, protecting against terminal-based injection attacks.
- [SAFE]: The skill follows the principle of least privilege by relying on standard AWS permissions and providing authoritative documentation links for remediation instead of executing autonomous repairs.
Audit Metadata