sglang-sota-performance

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to execute various shell commands, including deployment commands for SGLang, vLLM, and TensorRT-LLM servers, and performance benchmarking tools. It also involves running local Python scripts for data comparison (e.g., compare_benchmark_results.py in the llm-serving-auto-benchmark directory).\n- [PROMPT_INJECTION]: The skill is subject to Indirect Prompt Injection (Category 8) because it instructs the agent to ingest and analyze external data (benchmark results, JSONL files, and profiler traces) to inform decisions about code modifications.\n
  • Ingestion points: Benchmark logs, JSONL result files, and torch-profiler traces (SKILL.md).\n
  • Capability inventory: The skill allows the agent to write patches to the codebase and execute unit tests, integration tests, and benchmarks (SKILL.md).\n
  • Boundary markers: The skill does not provide specific instructions to use delimiters or ignore instructions that might be embedded in the performance data.\n
  • Sanitization: No mention of validation or sanitization of the performance artifacts is included before they are used to guide the patching process.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 01:19 AM
Security Audit — agent-trust-hub — sglang-sota-performance