modal
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill reference files provide examples of using
subprocess.runandsubprocess.Popenfor launching distributed training scripts and custom web servers like vLLM. - Evidence: Found in
references/gpu.mdandreferences/web-endpoints.md. - Context: These operations are described with explicit security warnings to keep argument lists fixed and avoid constructing commands from unsanitized user input.
- [EXTERNAL_DOWNLOADS]: The skill instructions detail the installation of the official Modal Python SDK and standard machine learning libraries (e.g., torch, transformers, vllm) from well-known registries.
- Evidence: Installation procedures are documented in
SKILL.md,references/getting-started.md, andreferences/images.md. - [INDIRECT_PROMPT_INJECTION]: The skill defines capabilities for creating web endpoints and scraping external content, which presents a surface for processing untrusted data.
- Evidence: Web endpoint and scraping examples are provided in
references/web-endpoints.mdandreferences/examples.md. - Mitigation: The instructions proactively recommend using
modal.Sandboxfor running untrusted workloads and implementing network egress restrictions via CIDR allowlists.
Audit Metadata