vast-gpu
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
sshwith-o StrictHostKeyChecking=noto interact with remote GPU instances. While this is a standard practice for managing dynamic cloud environments where host keys frequently change, it bypasses traditional host verification and introduces a theoretical risk of man-in-the-middle attacks. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes external data from project files to determine GPU requirements and construct command-line arguments for the
vastaiCLI. - Ingestion points: Reads requirements and model specifications from
refine-logs/EXPERIMENT_PLAN.md, local experiment scripts, and user-provided task descriptions. - Boundary markers: No specific delimiters or instructions are used to separate untrusted data from the agent's logic.
- Capability inventory: The skill uses
Bash(*),Read,Write,Edit,Grep, andGlobtools. - Sanitization: The skill lacks explicit sanitization routines for variables derived from file content before they are interpolated into shell commands, creating a potential vector for command injection if project files are malicious.
- [DYNAMIC_EXECUTION]: The skill utilizes
python3 -cto execute inline Python code for processing JSON output from thevastaiCLI. This is a common pattern for local data manipulation and does not involve executing external or untrusted scripts. - [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
vastaipackage viapipand downloads official Docker images (e.g.,pytorch/pytorch) to the rented instances. These are standard dependencies for the well-known vast.ai service.
Audit Metadata