qwen-qwen3-5

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides commands to monitor fleet status using curl and python3 -m json.tool. Although automated scanners flagged this as a potential remote code execution pattern, the use of the -m json.tool argument identifies this as a standard and safe practice for pretty-printing JSON data in the terminal.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the ollama-herd package via PyPI. This package is the core component of the tool documented by the skill and is provided by the skill's author, geeks-accelerator.
  • [SAFE]: No malicious patterns such as prompt injection, data exfiltration, or persistence mechanisms were detected. The skill's behavior is consistent with its stated purpose of managing a local LLM fleet.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 12:59 AM
Security Audit — agent-trust-hub — qwen-qwen3-5