flash

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents the installation of the runpod-flash package and its dependencies (such as torch, pandas, and diffusers) via standard package managers (pip, uv). These are well-known libraries and official vendor resources.
  • [COMMAND_EXECUTION]: The instructions guide the agent in using the flash CLI for infrastructure management tasks, including flash dev for local iteration with remote execution and flash deploy for shipping production endpoints. It provides safe patterns for backgrounding processes and log inspection.
  • [DYNAMIC_EXECUTION]: The skill facilitates the execution of user-defined Python functions on remote Runpod workers via the Endpoint SDK. This is the primary functionality of the tool and is documented with best practices for handling dependencies and model loading.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing user-supplied code and configuration for deployment. It provides clear boundary markers and instructions for managing secrets using environment variables, minimizing potential for unintended behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:46 PM
Security Audit — agent-trust-hub — flash