skills/aeondave/malskill/vec2text/Gen Agent Trust Hub

vec2text

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFE
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill includes examples using torch.load() to import embedding tensors from local storage. This is a standard operation in machine learning workflows, though it utilizes Python's pickle serialization format. As a best practice, users should ensure the files being loaded originate from trusted sources.
  • [EXTERNAL_DOWNLOADS]: The skill uses vec2text.load_pretrained_corrector("gtr-base"), which fetches pretrained models from Hugging Face. This is the intended behavior for the embedding-inversion task and uses a well-known model repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an interface for processing external data (embeddings and text strings).
  • Ingestion points: embeddings.pt file loading and list of strings in invert_strings.
  • Capability inventory: The skill converts data to text for user review; it does not pass output to dangerous commands, network calls, or write operations.
  • Boundary markers: None present.
  • Sanitization: None present.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:39 PM
Security Audit — agent-trust-hub — vec2text