vast-gpu

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses ssh with -o StrictHostKeyChecking=no to interact with remote GPU instances. While this is a standard practice for managing dynamic cloud environments where host keys frequently change, it bypasses traditional host verification and introduces a theoretical risk of man-in-the-middle attacks.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes external data from project files to determine GPU requirements and construct command-line arguments for the vastai CLI.
  • Ingestion points: Reads requirements and model specifications from refine-logs/EXPERIMENT_PLAN.md, local experiment scripts, and user-provided task descriptions.
  • Boundary markers: No specific delimiters or instructions are used to separate untrusted data from the agent's logic.
  • Capability inventory: The skill uses Bash(*), Read, Write, Edit, Grep, and Glob tools.
  • Sanitization: The skill lacks explicit sanitization routines for variables derived from file content before they are interpolated into shell commands, creating a potential vector for command injection if project files are malicious.
  • [DYNAMIC_EXECUTION]: The skill utilizes python3 -c to execute inline Python code for processing JSON output from the vastai CLI. This is a common pattern for local data manipulation and does not involve executing external or untrusted scripts.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the vastai package via pip and downloads official Docker images (e.g., pytorch/pytorch) to the rented instances. These are standard dependencies for the well-known vast.ai service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:08 PM
Security Audit — agent-trust-hub — vast-gpu