hyperpod-ssm
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the AWS CLI to execute shell commands on remote SageMaker HyperPod instances via the AWS-StartNonInteractiveCommand SSM document. This is the designated primary interface for cluster node management where direct SSH is restricted.
- [PRIVILEGE_ESCALATION]: Documentation acknowledges that SSM commands execute with root privileges by default on target nodes and provides guidance on using sudo for non-root execution.
- [INDIRECT_PROMPT_INJECTION]: The skill accepts command strings and paths from the calling agent. Ingestion points: command line arguments in ssm-exec.sh ($CMD, $LOCAL_PATH, $REMOTE_PATH). Boundary markers: None; commands are executed via bash -c on the remote host. Capability inventory: Remote shell execution, file read/write, and system diagnostics. Sanitization: Uses jq @sh for shell-safe path quoting and jq --arg for building JSON command payloads.
- [DYNAMIC_EXECUTION]: The ssm-exec.sh script dynamically generates JSON payloads for the SSM API and writes them to temporary files with restricted permissions (chmod 600) before execution. It also handles dynamic data transport using Base64 and GZIP.
Audit Metadata