classifier-lab

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The script scripts/train.py utilizes torch.load with weights_only=False in the evaluate_vision function. This configuration is insecure as it allows for the execution of arbitrary Python code during the deserialization of model checkpoints. An attacker could exploit this by providing a specially crafted malicious model file.
  • [COMMAND_EXECUTION]: The skill frequently uses the subprocess module to orchestrate its workflows. In bridge.py, user-provided paths and parameters are passed to shell commands. More critically, scripts/benchmark.py constructs shell command strings using f-strings in the _taxonomy_extract function (e.g., bash -lc command), which includes the taxonomy_collection variable. This pattern is vulnerable to command injection if input parameters are not strictly sanitized.
  • [EXTERNAL_DOWNLOADS]: The skill dynamically downloads pre-trained model weights from HuggingFace and PyTorch Hub via the timm and transformers libraries. The run.sh script also initiates package installations using uv pip install at runtime. While these sources are generally well-known, the automated execution of external code and fetching of large binary artifacts increases the attack surface.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface. It ingests untrusted data from user-provided JSONL files (Category 8). The summaries of this data are then passed to other agent skills (taxonomy and memory) via shell commands without explicit boundary markers or robust sanitization between the data content and the command structure. This could allow malicious instructions embedded in a dataset to influence the agent's behavior during the extraction or learning phases.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — classifier-lab