dstack-prototyping

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches technical documentation and configuration recipes from several external domains, including dstack.ai, vllm.ai, sglang.io, lmsys.org, and github.com. These sources are used to inform the agent's choice of backends, images, and launch flags.
  • [COMMAND_EXECUTION]: The skill involves the execution of shell commands within dstack tasks and services. It provides templates for starting long-running server processes (e.g., using nohup and vllm serve) and instructs the agent to verify functionality by sending local requests to these services.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it ingests content from external documentation sites to guide command construction. This risk is inherent to skills that fetch real-time technical guidance but is mitigated here by the use of reputable, framework-specific sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 05:02 PM
Security Audit — agent-trust-hub — dstack-prototyping