modal
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides recipes in its documentation that use
subprocess.Popenwithshell=Trueto launch server processes such as vLLM. While common for containerized workloads, this pattern is susceptible to command injection if parameters like model identifiers are derived from untrusted user inputs without sanitization.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines functions that ingest and process external data, creating a potential attack surface for indirect prompt injection.\n - Ingestion points: Function parameters such as the
urlargument in thefetchfunction (SKILL.md) and model configuration strings in theservefunction (references/web-and-scaling.md).\n - Boundary markers: The provided code templates do not include specific delimiters or instructions to ignore embedded commands in external data.\n
- Capability inventory: The skill facilitates network operations using the
requestslibrary, persistent file storage viamodal.Volume, and shell command execution viasubprocess.Popen.\n - Sanitization: The examples do not demonstrate input validation, escaping, or sanitization logic for data processed by the functions.
Audit Metadata