skills/ericrisco/rsc-harness/ollama/Gen Agent Trust Hub

ollama

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a shell utility (scripts/verify.sh) designed to perform static analysis on local project files. The script uses standard Unix tools such as find, grep, awk, and sed to lint Modelfile syntax and verify that application code correctly points to local Ollama endpoints. All operations are read-only relative to the project files.
  • [COMMAND_EXECUTION]: Documentation in SKILL.md provides standard administrative commands for the ollama CLI, such as serve, pull, run, and ps, which are necessary for the skill's primary function of local model management.
  • [DATA_EXPOSURE]: The skill follows security best practices by instructing the user to use a dummy API key when connecting to the local OpenAI-compatible API layer, preventing the accidental use or exposure of real production credentials.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and benchmarks from well-known and trusted sources, including the ggml-org (llama.cpp) GitHub repository and the official Ollama blog. These references are purely informational.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:57 AM
Security Audit — agent-trust-hub — ollama