Terradev GPU Cloud

PassAudited by VirusTotal on May 14, 2026.

Findings (1)

The skill is classified as suspicious due to its requirement for extensive and highly sensitive cloud API keys (e.g., AWS, GCP, Azure, Oracle, RunPod) and its ability to provision and manage significant cloud infrastructure, including executing arbitrary commands on remote GPU instances. While the `SKILL.md` explicitly states 'BYOAPI — your keys never leave your machine' and includes strong safety instructions for the AI agent ('Never auto-provision without user confirmation'), the inherent power and broad permissions required for its stated purpose (cross-cloud GPU provisioning) represent a high-risk capability. There is no evidence of intentional malicious behavior, but the potential for misuse or vulnerabilities in the underlying `terradev-cli` (not provided for analysis) makes it more than benign.