classifier-lab-subagent
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The orchestrator and harness scripts utilize
asyncio.create_subprocess_execandsubprocess.runto manage training loops. - Evidence found in
harness.py(lines 280-289) andorchestrator.py(lines 352, 428) shows the skill spawning Python processes to execute dynamically generated training scripts (train.py) and checking GPU status. - [EXTERNAL_DOWNLOADS]: The training scripts download datasets and pre-trained models from HuggingFace at runtime.
- Evidence found in
harness.py(line 125, 147) andorchestrator.py(line 166, 184) where thedatasetsandtransformerslibraries are used to load theag_newsdataset and various model backbones (e.g.,distilbert-base-uncased). - [INDIRECT_PROMPT_INJECTION]: The skill ingests structured JSON data from a local service (
scillmon port 4001) to adjust training parameters. - Ingestion points:
harness.py(lines 208-223) andorchestrator.py(lines 321-345) make POST requests tohttp://localhost:4001/v1/chat/completions. - Boundary markers: The skill uses
response_format": {"type": "json_object"}to enforce structured output from the LLM. - Capability inventory: The ingested data (learning rate, batch size, etc.) is interpolated into training configurations but is not used directly in shell commands or
eval()calls. - Sanitization: The skill employs a heuristic fallback (lines 228-234 in
harness.py) if the external service returns invalid data or fails, providing a safety layer against unexpected input.
Audit Metadata