modal-serverless-gpu

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides templates for creating inference endpoints and classes (e.g., TextGenerator in SKILL.md and InferenceService in references/advanced-usage.md) that ingest raw text prompts from external sources. If an agent uses these components to process untrusted data without proper sanitization or boundary markers, it may be vulnerable to indirect instructions.
  • Ingestion points: SKILL.md (TextGenerator generate method), references/advanced-usage.md (predict method).
  • Boundary markers: Absent in provided code snippets.
  • Capability inventory: The skill enables cloud container execution, persistent volume access (modal.Volume), and network communication via web endpoints.
  • Sanitization: Not implemented in the example code.
  • [DYNAMIC_EXECUTION]: The documentation describes the use of modal.Sandbox, which allows for the execution of arbitrary commands within cloud environments at runtime.
  • Evidence: references/advanced-usage.md demonstrates sandbox.exec for running shell commands.
  • [COMMAND_EXECUTION]: Example scripts include the use of subprocess.run to execute system commands for diagnostics and to launch distributed training processes.
  • Evidence: Found in SKILL.md (nvidia-smi) and references/advanced-usage.md (torch.distributed.launch).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — modal-serverless-gpu