training-llms-megatron
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requires the agent to execute shell commands using
torchrunandsbatchfor launching distributed training jobs. These are standard operations for ML engineering workflows. - Evidence: Multiple shell script examples and
torchruncommands are provided throughoutSKILL.mdand the reference files. - [EXTERNAL_DOWNLOADS]: The skill instructs the installation of standard machine learning libraries and the use of official NVIDIA Docker containers.
- Evidence:
pip install megatron-coreanddocker run nvcr.io/nvidia/pytorch:25.04-py3inSKILL.md. - Context: These are well-known, official sources (NVIDIA) and represent standard practice.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing large external datasets for training, which could theoretically contain malicious instructions.
- Ingestion points: The
--data-pathparameter in training scripts (found inSKILL.mdandreferences/training-recipes.md). - Boundary markers: None specified; standard ML training typically does not use NL delimiters for raw data tokens.
- Capability inventory: The skill has the capability to write local shell scripts, execute system commands (
torchrun), and initiate network communication for distributed training. - Sanitization: Not applicable as the data is consumed by low-level ML training loops rather than an LLM prompt processor.
- [SAFE]: The skill is a high-quality educational and operational resource for ML training that adheres to safety and integrity rules. It uses trusted industry references such as NVIDIA, Meta, and Microsoft.
Audit Metadata