ray-train
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard orchestration patterns for distributed machine learning using the well-known Ray framework. All code examples for PyTorch, HuggingFace, and Ray Tune use official APIs and follow established developer documentation.
- [SAFE]: External dependencies and references, such as the Ray GitHub repository, official documentation (docs.ray.io), and the KubeRay Helm repository, are sourced from trusted organizations and well-known services. The use of 'ray[train]', 'torch', and 'transformers' represents standard package installation for the stated purpose.
- [DATA_EXPOSURE]: The cluster configuration examples in 'references/multi-node.md' include placeholders for cloud provider IDs and common SSH key paths (e.g., '~/.ssh/id_rsa'). These are identified as standard documentation practices for authentication in cloud environments and do not represent a malicious attempt to exfiltrate credentials.
- [DYNAMIC_EXECUTION]: The skill demonstrates 'torch.load()' for model checkpointing. While PyTorch's pickle-based loading has inherent security risks when processing untrusted files, this is documented as a standard feature for fault-tolerant training. The skill's 'Agent operating procedure' mitigates this by instructing the agent to validate results and confirm inputs.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a standard attack surface for ML orchestration tools, as it ingests user-defined configurations and external model weights.
- Ingestion points: Training configuration dictionaries ('config') and remote model identifiers ('gpt2') in 'SKILL.md'.
- Boundary markers: The skill relies on the agent's internal guardrails and the explicit 'Integrity rules' provided in the operating procedure.
- Capability inventory: Cluster worker orchestration, file writing (checkpoints), and network communication for distributed synchronization.
- Sanitization: No specific sanitization logic is provided in the templates, which is typical for developer-centric orchestration scripts.
Audit Metadata