classifier-lab-subagent

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The orchestrator and harness scripts utilize asyncio.create_subprocess_exec and subprocess.run to manage training loops.
  • Evidence found in harness.py (lines 280-289) and orchestrator.py (lines 352, 428) shows the skill spawning Python processes to execute dynamically generated training scripts (train.py) and checking GPU status.
  • [EXTERNAL_DOWNLOADS]: The training scripts download datasets and pre-trained models from HuggingFace at runtime.
  • Evidence found in harness.py (line 125, 147) and orchestrator.py (line 166, 184) where the datasets and transformers libraries are used to load the ag_news dataset and various model backbones (e.g., distilbert-base-uncased).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests structured JSON data from a local service (scillm on port 4001) to adjust training parameters.
  • Ingestion points: harness.py (lines 208-223) and orchestrator.py (lines 321-345) make POST requests to http://localhost:4001/v1/chat/completions.
  • Boundary markers: The skill uses response_format": {"type": "json_object"} to enforce structured output from the LLM.
  • Capability inventory: The ingested data (learning rate, batch size, etc.) is interpolated into training configurations but is not used directly in shell commands or eval() calls.
  • Sanitization: The skill employs a heuristic fallback (lines 228-234 in harness.py) if the external service returns invalid data or fails, providing a safety layer against unexpected input.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — classifier-lab-subagent