modal-serverless-gpu
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides templates for creating inference endpoints and classes (e.g.,
TextGeneratorinSKILL.mdandInferenceServiceinreferences/advanced-usage.md) that ingest raw text prompts from external sources. If an agent uses these components to process untrusted data without proper sanitization or boundary markers, it may be vulnerable to indirect instructions. - Ingestion points:
SKILL.md(TextGenerator generate method),references/advanced-usage.md(predict method). - Boundary markers: Absent in provided code snippets.
- Capability inventory: The skill enables cloud container execution, persistent volume access (
modal.Volume), and network communication via web endpoints. - Sanitization: Not implemented in the example code.
- [DYNAMIC_EXECUTION]: The documentation describes the use of
modal.Sandbox, which allows for the execution of arbitrary commands within cloud environments at runtime. - Evidence:
references/advanced-usage.mddemonstratessandbox.execfor running shell commands. - [COMMAND_EXECUTION]: Example scripts include the use of
subprocess.runto execute system commands for diagnostics and to launch distributed training processes. - Evidence: Found in
SKILL.md(nvidia-smi) andreferences/advanced-usage.md(torch.distributed.launch).
Audit Metadata