hf-cloud-serving-image-selection
Pick the right serving container for a SageMaker model deployment and find its current image URI. Use this skill whenever about to deploy a model to a SageMaker endpoint and an image URI needs to be chosen — including when the user says "deploy this LLM", "host this HuggingFace model", "serve thi...
Install this skill
or
34/100
Security score
The hf-cloud-serving-image-selection skill was audited on Oct 1, 2026 and we found 6 security issues across 3 threat categories, including 1 critical. Review the findings below before installing.
Categories Tested
Security Issues
low line 172
Command substitution pattern
SourceSKILL.md
| 170 | ```bash |
| 171 | # macOS / Linux |
| 172 | PRIVATE_URI=$(python3 scripts/mirror_image.py \ |
| 173 | public.ecr.aws/deep-learning-containers/vllm:<tag> \ |
| 174 | vllm-mirror) |
medium line 65
Curl to non-GitHub URL
SourceSKILL.md
| 63 | |
| 64 | ```bash |
| 65 | curl -s https://huggingface.co/<model-id>/raw/main/config.json |
| 66 | # "architectures": ["Qwen3ForCausalLM"] → vLLM |
| 67 | # "architectures": ["XLMRobertaForSequenceClassification"] → TEI |
medium line 189
Curl to non-GitHub URL
SourceSKILL.md
| 187 | 1. **The catalog's source data on GitHub** — the page is generated from one YAML file per version, listing exact tags, CUDA, and Python versions. List a family's files, then fetch the newest: |
| 188 | ```bash |
| 189 | curl -s https://api.github.com/repos/aws/deep-learning-containers/contents/docs/src/data/huggingface-vllm |
| 190 | curl -s https://raw.githubusercontent.com/aws/deep-learning-containers/main/docs/src/data/huggingface-vllm/0.21.0-gpu-sagemaker.yml |
| 191 | ``` |
critical line 166
Access to AWS credentials directory
SourceSKILL.md
| 164 | SageMaker endpoints inside a VPC **without** a NAT gateway can't pull from `public.ecr.aws`. The deployment fails with an image-pull error that doesn't mention "VPC" or "egress". |
| 165 | |
| 166 | For images on AWS's regional ECR (everything in the catalog): SageMaker reaches them through built-in routing, no NAT needed. Use the regional URI pattern (`<account>.dkr.ecr.<region>.amazonaws.com/...`), not the `public.ecr.aws/...` pattern. |
| 167 | |
| 168 | For images requiring `public.ecr.aws` access (less common): mirror to a private ECR repo in your account with `scripts/mirror_image.py` (cross-platform; needs Docker + the `aws` CLI). Run it from the shell where the AWS CLI works. |
high line 173
Access to AWS credentials directory
SourceSKILL.md
| 171 | # macOS / Linux |
| 172 | PRIVATE_URI=$(python3 scripts/mirror_image.py \ |
| 173 | public.ecr.aws/deep-learning-containers/vllm:<tag> \ |
| 174 | vllm-mirror) |
| 175 | ``` |
high line 180
Access to AWS credentials directory
SourceSKILL.md
| 178 | # Windows (PowerShell) — capture stdout into a variable |
| 179 | $PRIVATE_URI = python scripts\mirror_image.py ` |
| 180 | public.ecr.aws/deep-learning-containers/vllm:<tag> vllm-mirror |
| 181 | ``` |
| 182 |
Scanned on Oct 1, 2026
View Security Dashboard