vastai-debug-bundle

Pass

Audited by Gen Agent Trust Hub on Mar 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard local commands including grep, tar, and sed to collect diagnostic logs and package them into a compressed archive.
  • [EXTERNAL_DOWNLOADS]: Includes a connectivity test using curl targeting the official api.vastai.com health endpoint. This is a well-known service associated with the skill's purpose.
  • [CREDENTIALS_UNSAFE]: While the skill reads sensitive files like .env, it implements automated redaction via sed to mask secrets and ensures the VASTAI_API_KEY is only reported as set rather than exposed.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 4, 2026, 01:54 PM