optimize-for-gpu

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided Python code and data to provide optimization recommendations, creating an inherent attack surface for indirect prompt injection.
  • Ingestion points: User-provided numerical and scientific Python code (NumPy, pandas, SciPy, etc.) and dataset descriptions in the conversation context (SKILL.md, references/code_transformation_patterns.md).
  • Boundary markers: The instructions do not specify explicit delimiters or warnings for the agent to ignore instructions embedded within user code or data comments.
  • Capability inventory: The skill includes instructions for package installation via uv add (references/installation.md), shell command execution for profiling (e.g., nsys, ncu), and Python code execution for benchmarking and data processing.
  • Sanitization: No instructions are present for sanitizing or escaping content from user-provided code snippets before processing.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install numerous GPU-accelerated libraries from official package registries.
  • Evidence: Installation commands in references/installation.md use uv add with --extra-index-url=https://pypi.nvidia.com for packages such as cugraph-cu12, cuml-cu12, and cuvs-cu12. These target official NVIDIA infrastructure, which is a well-known and trusted service.
  • [DYNAMIC_EXECUTION]: The skill utilizes Just-In-Time (JIT) compilation and data serialization techniques common in high-performance computing.
  • Evidence: Extensive use of JIT compilation via Numba-CUDA (@cuda.jit) and NVIDIA Warp (@wp.kernel) is documented in references/numba.md and references/warp.md. Additionally, references/cuml.md provides patterns for model serialization using the standard pickle module.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — optimize-for-gpu