vastai-data-handling
Provides patterns for secure data transfer, redaction, and compliance when using shared GPU hardware on Vast.ai.
Install
mkdir -p .claude/skills/vastai-data-handling && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/7835" && unzip -o skill.zip -d .claude/skills/vastai-data-handling && rm skill.zipInstalls to .claude/skills/vastai-data-handling
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Manage training data and model artifacts securely on Vast.ai GPU instances.Key capabilities
- →Transfer training data using SCP or compressed archives
- →Encrypt datasets locally before transfer with AES-256
- →Manage model checkpoints using S3 cloud storage
- →Clean sensitive data and command history before instance destruction
- →Implement data lifecycle policies for logs and artifacts
How it works
It provides patterns for secure data movement, encryption, and cloud-based checkpointing to handle the transient nature of rented GPU hardware. It includes scripts to sanitize the workspace and clear history before instance termination.
Inputs & outputs
When to use vastai-data-handling
- →Securely transferring sensitive training data
- →Implementing data retention policies
- →Ensuring GDPR compliance for GPU workloads
About this skill
Recoverable Vast.ai Data Movement
Overview
Disposable instance storage is a working tier, not the system of record. Choose the supported location syntax, verify checksums, use trusted datacenters for sensitive cloud sync, and externalize recovery artifacts before stop, expiry, or destroy.
Prerequisites
- Classified source, destination, size, checksum, encryption, and retention requirements
- Approved local, instance, volume, or saved cloud-connection identifiers
- Recovery point objective and owner for copy verification and cleanup
Instructions
Step 1: Plan the route
Choose local:, C.instance:path, V.volume:path, or saved cloud connection syntax based on the documented supported directions. Do not assume volumes can copy directly to local.
Step 2: Prepare least privilege
Scope the Vast.ai control key and cloud credential to the required operation and prefix. Prefer a trusted datacenter for sensitive Cloud Sync.
Step 3: Transfer into a staging path
Copy to a versioned temporary destination with enough disk and bandwidth budget. Never target /root or /, which can break SSH permissions and future copies.
Step 4: Verify before promotion
Compare size, count, cryptographic checksums, and a workload-level sample before renaming or consuming the staged data.
Step 5: Checkpoint externally
Write checkpoints and final artifacts to a recoverable volume or cloud target at a cadence inside the recovery objective.
Step 6: Close retention
Verify the external copy, remove temporary credentials, and destroy or retain instance/volume data according to policy; record ongoing storage cost.
Authentication
Keep storage credentials distinct from VAST_API_KEY, prefix-scoped, and short-lived. Never place either credential in copy logs, image layers, or evidence manifests.
Tool Discipline
Use Read and Grep to inspect manifests, configuration, provider output, and existing tests before proposing a mutation. Use Write or Edit only for the approved plan, implementation, test, or redacted receipt; do not create, update, destroy, or fund Vast.ai resources without explicit operator approval.
Output
- Source/destination route and data-class decision
- Transfer, checksum, checkpoint, and recovery evidence
- Retention, credential revocation, and residual-storage receipt
Return location types and IDs, byte/file counts, checksums, checkpoint age, verification result, and remaining storage owner.
Examples
A training dataset moves from a saved cloud connection to C.123:/workspace/data, is verified in a staging directory, and checkpoints return to a run-specific cloud prefix before the instance is destroyed.
Error Handling
| Failure | Response |
|---|---|
| Requested route is unsupported | Choose a documented intermediate instance, volume, or cloud path. |
| Checksum differs | Quarantine the destination and repeat from a known source; do not train on it. |
| Instance is nearing expiry or failure | Prioritize external checkpoint recovery and record any unrecoverable window. |
| Credential is broader than the prefix | Stop the transfer and issue a narrower credential. |
Resources
When not to use it
- →Storing sensitive data permanently on rented GPU instances
- →Relying on instance local storage for long-term data retention
Prerequisites
Limitations
- →Instances run on shared hardware operated by third-party hosts
- →Temporary files in /tmp are automatically deleted on destroy
How it compares
Unlike manual file transfers, this approach enforces encryption and automated cleanup to mitigate risks associated with shared third-party hardware.
Compared to similar skills
vastai-data-handling side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| vastai-data-handling (this skill) | 1 | 2mo | Review | Intermediate |
| 1password | 27 | 4mo | Review | Intermediate |
| senior-security | 31 | 9mo | Review | Advanced |
| fix-dependabot-alerts | 18 | 8mo | Review | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
1password
openclaw
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.
senior-security
davila7
Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.
fix-dependabot-alerts
microsoft
Fix Dependabot security alerts by updating vulnerable npm dependencies. Use when the user mentions "dependabot", "security alerts", "vulnerability", "CVE", or wants to update packages with security issues.
red-team-tools-and-methodology
davila7
This skill should be used when the user asks to "follow red team methodology", "perform bug bounty hunting", "automate reconnaissance", "hunt for XSS vulnerabilities", "enumerate subdomains", or needs security researcher techniques and tool configurations from top bug bounty hunters.
wsdiscovery
BrownFineSecurity
WS-Discovery protocol scanner for discovering and enumerating ONVIF cameras and IoT devices on the network. Use when you need to discover ONVIF devices, cameras, or WS-Discovery enabled equipment on a network.
trivy-offline-vulnerability-scanning
benchflow-ai
Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files. This skill covers setting up offline scanning, executing Trivy against package lock files, and generating JSON vulnerability reports without requiring internet access.