skills/openlair/dr-claw/aris-vast-gpu/Gen Agent Trust Hub

aris-vast-gpu

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs extensive shell operations to manage remote infrastructure. This includes using the vastai CLI for instance lifecycle management and standard networking utilities (ssh, scp, rsync) for code synchronization and remote environment setup.
  • [PROMPT_INJECTION]: The skill implements an indirect prompt injection surface as it ingests untrusted data from project files and scripts to automate decision-making regarding hardware procurement.
  • Ingestion points: The skill reads refine-logs/EXPERIMENT_PLAN.md and various experiment scripts to determine GPU and storage requirements (SKILL.md).
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard malicious directives that might be embedded within the processed experiment files.
  • Capability inventory: The skill possesses broad capabilities including full shell access (Bash(*)) and the ability to execute arbitrary commands on remote hosts via SSH.
  • Sanitization: No sanitization or validation logic is defined for the content extracted from external data sources prior to its use in calculating provisioning requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 01:42 AM
Security Audit — agent-trust-hub — aris-vast-gpu