pytorch-fsdp
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as a static documentation resource for PyTorch FSDP development. All included content is technical in nature and derived from established official documentation.
- [SAFE]: Dependencies are limited to standard, reputable machine learning libraries including
torchandtransformers. - [INDIRECT_PROMPT_INJECTION]: The skill processes large documentation files (e.g.,
references/common-patterns.md) to provide context for the agent. This represents a standard information retrieval surface. - Ingestion points: The agent reads technical documentation from the
references/directory to answer queries. - Boundary markers: Content is naturally delimited by Markdown formatting and structured patterns.
- Capability inventory: The skill enables the agent to assist in code development, sharding strategies, and debugging based on the provided reference material.
- Sanitization: No specific input sanitization is implemented, which is standard for static reference skills.
- [SAFE]: The documentation includes explicit security warnings regarding the use of the
picklemodule for distributed communication (e.g.,recv_object_list), correctly identifying and advising against the risks of arbitrary code execution when unpickling untrusted data.
Audit Metadata