fireworks-training

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a documentation and shared reference carrier for the Fireworks training platform. It contains no executable code of its own, but rather provides users with guides and commands to interact with the Fireworks API.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the firectl CLI and Python libraries from the vendor's own official repositories (GitHub fw-ai organization). These are trusted resources belonging to the skill author.
  • [PROMPT_INJECTION]: A heuristic detector flagged a 'concealment' pattern in references/rl-sampling-timeouts.md. Review confirms this is a false positive; the text describes a security feature that prevents the logging of sensitive data (like prompts and API keys) to ensure user privacy.
  • [DATA_EXFILTRATION]: Telemetry via PostHog is documented in references/telemetry-notice.md. The documentation includes a clear privacy notice and instructions on how to opt-out using the TELEMETRY_OPT_OUT environment variable. The telemetry is scoped to metadata and excludes sensitive training content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 01:29 AM
Security Audit — agent-trust-hub — fireworks-training