training-llms-megatron

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the agent to execute shell commands using torchrun and sbatch for launching distributed training jobs. These are standard operations for ML engineering workflows.
  • Evidence: Multiple shell script examples and torchrun commands are provided throughout SKILL.md and the reference files.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of standard machine learning libraries and the use of official NVIDIA Docker containers.
  • Evidence: pip install megatron-core and docker run nvcr.io/nvidia/pytorch:25.04-py3 in SKILL.md.
  • Context: These are well-known, official sources (NVIDIA) and represent standard practice.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing large external datasets for training, which could theoretically contain malicious instructions.
  • Ingestion points: The --data-path parameter in training scripts (found in SKILL.md and references/training-recipes.md).
  • Boundary markers: None specified; standard ML training typically does not use NL delimiters for raw data tokens.
  • Capability inventory: The skill has the capability to write local shell scripts, execute system commands (torchrun), and initiate network communication for distributed training.
  • Sanitization: Not applicable as the data is consumed by low-level ML training loops rather than an LLM prompt processor.
  • [SAFE]: The skill is a high-quality educational and operational resource for ML training that adheres to safety and integrity rules. It uses trusted industry references such as NVIDIA, Meta, and Microsoft.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — training-llms-megatron