modal

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill reference files provide examples of using subprocess.run and subprocess.Popen for launching distributed training scripts and custom web servers like vLLM.
  • Evidence: Found in references/gpu.md and references/web-endpoints.md.
  • Context: These operations are described with explicit security warnings to keep argument lists fixed and avoid constructing commands from unsanitized user input.
  • [EXTERNAL_DOWNLOADS]: The skill instructions detail the installation of the official Modal Python SDK and standard machine learning libraries (e.g., torch, transformers, vllm) from well-known registries.
  • Evidence: Installation procedures are documented in SKILL.md, references/getting-started.md, and references/images.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines capabilities for creating web endpoints and scraping external content, which presents a surface for processing untrusted data.
  • Evidence: Web endpoint and scraping examples are provided in references/web-endpoints.md and references/examples.md.
  • Mitigation: The instructions proactively recommend using modal.Sandbox for running untrusted workloads and implementing network egress restrictions via CIDR allowlists.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — modal