serverless-modal

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill's primary function is to generate and execute Python code on Modal's remote infrastructure using the modal run and modal deploy commands. This is the intended purpose of the skill and targets the official Modal platform.
  • [COMMAND_EXECUTION]: The skill utilizes the local environment to install the modal CLI via pip and perform authentication and deployment tasks.
  • [DYNAMIC_EXECUTION]: The skill generates Python scripts (launcher files) at runtime which are then executed. This is a standard workflow for integrating with the Modal SDK.
  • [INDIRECT_PROMPT_INJECTION]: The skill interpolates user-supplied task descriptions into its workflow, creating a potential surface for indirect instructions to influence generated code.
  • Ingestion points: The $ARGUMENTS variable in SKILL.md captures user task descriptions.
  • Boundary markers: None present around the interpolated input.
  • Capability inventory: File writing (Edit/Write), Bash command execution (pip, modal CLI), and remote code execution on GPU clusters.
  • Sanitization: No automated sanitization is present, though the skill provides explicit documentation and cost-estimation steps to require human oversight before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:07 PM
Security Audit — agent-trust-hub — serverless-modal