create-gpt

Warn

Audited by Snyk on Mar 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly loads pretrained models and tokenizer code from public model hubs (e.g., AutoModelForCausalLM.from_pretrained(spec.base_model) and AutoTokenizer.from_pretrained(..., trust_remote_code=True) in scripts such as scripts/hp_search.py, scripts/evaluate.py, scripts/export_gguf.py and scripts/infer.py), which fetches untrusted third‑party model/code from the open web that the agent executes/uses for training and inference and can thus materially change behavior.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill calls Transformers' from_pretrained(spec.base_model, trust_remote_code=True) at runtime (e.g., will fetch and execute code from the Hugging Face model repo https://huggingface.co/Qwen/Qwen2.5-1.5B-Instruct), which downloads remote code that can be executed and is relied on as a required dependency.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:35 AM
Issues
2
Security Audit — snyk — create-gpt