create-gpt
Warn
Audited by Snyk on Mar 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly loads pretrained models and tokenizer code from public model hubs (e.g., AutoModelForCausalLM.from_pretrained(spec.base_model) and AutoTokenizer.from_pretrained(..., trust_remote_code=True) in scripts such as scripts/hp_search.py, scripts/evaluate.py, scripts/export_gguf.py and scripts/infer.py), which fetches untrusted third‑party model/code from the open web that the agent executes/uses for training and inference and can thus materially change behavior.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill calls Transformers' from_pretrained(spec.base_model, trust_remote_code=True) at runtime (e.g., will fetch and execute code from the Hugging Face model repo https://huggingface.co/Qwen/Qwen2.5-1.5B-Instruct), which downloads remote code that can be executed and is relied on as a required dependency.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata