hyperpod-slurm-debugger

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed with a strictly read-only constraint, explicitly prohibiting state-mutating commands. Diagnostics are performed via bundled scripts using authenticated AWS CLI calls, ensuring no unauthorized changes are made to the cluster.
  • [SAFE]: The slurm-diagnose.sh script implements rigorous validation for all parameters (region, cluster name, node names, instance IDs) using specific regular expression patterns before they are used in shell commands, mitigating local injection risks.
  • [SAFE]: Interaction with cluster nodes via AWS Systems Manager (SSM) utilizes a secure wrapper that Base64-encodes the diagnostic payload and uses jq @sh to safely quote environment variables, preventing remote command injection on the target instances.
  • [SAFE]: The script includes a sanitization helper that strips ANSI escape sequences and control characters from server-derived data before outputting to the user's terminal, protecting against terminal-based injection attacks.
  • [SAFE]: The skill follows the principle of least privilege by relying on standard AWS permissions and providing authoritative documentation links for remediation instead of executing autonomous repairs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:58 PM
Security Audit — agent-trust-hub — hyperpod-slurm-debugger