keras
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to load and process external model files (e.g., .keras, .h5, SavedModel). This represents a surface for indirect prompt injection if the model file contains malicious metadata or architecture configurations. However, the skill mitigates this by explicitly recommending the use of safe loading protocols.\n
- Ingestion points: The load_model() function in SKILL.md processes external files.\n
- Boundary markers: The skill includes explicit instructions to maintain safe_mode=True to ignore untrusted custom objects.\n
- Capability inventory: The skill performs model.summary(), get_config(), and layer.get_weights(), which are primarily read-only inspection capabilities.\n
- Sanitization: The documentation warns that custom layers or metrics require explicit trust, promoting a conservative security posture.\n- [DYNAMIC_EXECUTION]: Loading deep learning models involves the deserialization of complex objects and configurations. The skill addresses the inherent risk of arbitrary code execution during deserialization.\n
- Pattern: The code examples demonstrate the use of load_model(..., safe_mode=True), which is the standard mechanism to prevent the execution of arbitrary Python code (such as Lambda layers) embedded in untrusted model files.
Audit Metadata