classifier-lab
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The script
scripts/train.pyutilizestorch.loadwithweights_only=Falsein theevaluate_visionfunction. This configuration is insecure as it allows for the execution of arbitrary Python code during the deserialization of model checkpoints. An attacker could exploit this by providing a specially crafted malicious model file. - [COMMAND_EXECUTION]: The skill frequently uses the
subprocessmodule to orchestrate its workflows. Inbridge.py, user-provided paths and parameters are passed to shell commands. More critically,scripts/benchmark.pyconstructs shell command strings using f-strings in the_taxonomy_extractfunction (e.g.,bash -lc command), which includes thetaxonomy_collectionvariable. This pattern is vulnerable to command injection if input parameters are not strictly sanitized. - [EXTERNAL_DOWNLOADS]: The skill dynamically downloads pre-trained model weights from HuggingFace and PyTorch Hub via the
timmandtransformerslibraries. Therun.shscript also initiates package installations usinguv pip installat runtime. While these sources are generally well-known, the automated execution of external code and fetching of large binary artifacts increases the attack surface. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface. It ingests untrusted data from user-provided JSONL files (Category 8). The summaries of this data are then passed to other agent skills (taxonomy and memory) via shell commands without explicit boundary markers or robust sanitization between the data content and the command structure. This could allow malicious instructions embedded in a dataset to influence the agent's behavior during the extraction or learning phases.
Audit Metadata