vllm-setup
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill pulls the vLLM container image from the official NVIDIA Container Registry (nvcr.io). This is a standard deployment procedure using vendor-official infrastructure.
- [COMMAND_EXECUTION]: The skill provides shell commands for hardware inspection (nvidia-smi) and container management (docker run/logs). These commands are necessary for the skill's primary purpose of setting up an inference server and are restricted to standard administrative tasks.
- [CREDENTIALS_UNSAFE]: The skill facilitates the use of a Hugging Face token (HF_TOKEN) for model authentication. It instructs the user to provide the token to the container environment, which is the standard method for accessing gated models. No evidence of silent harvesting or exfiltration was found.
Audit Metadata