unsloth
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied training data in JSONL format. This represents an inherent attack surface for indirect prompt injection where malicious instructions in the dataset could influence the model's behavior. The skill mitigates this by providing specific instructions and code for applying chat templates and masking the instruction/user portion of the data using
train_on_responses_only, ensuring the model only learns from the intended assistant responses.\n- [EXTERNAL_DOWNLOADS]: The skill includes instructions to download theunslothlibrary and pre-quantized models from Hugging Face. These are legitimate resources required for the skill's functionality and are sourced from reputable locations.\n- [COMMAND_EXECUTION]: Standard shell commands are used for library installation and version verification. These commands are transparent and necessary for the setup of the development environment.
Audit Metadata