create-intent-map
Warn
Audited by Snyk on Mar 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly downloads and loads third‑party models/code from the public HuggingFace hub (e.g., AutoModelForCausalLM.from_pretrained(DEFAULT_BASE_MODEL) with HF_TOKEN referenced in SKILL.md/run.sh and trust_remote_code=True) and also calls external LLM services (scillm/Chutes via call_chutes/ScillmClient and Ollama endpoints) whose outputs are parsed and used in variation generation, evaluation, and reward signals—untrusted content that can materially alter training/inference behavior.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill repeatedly calls transformers.from_pretrained with model IDs (e.g., deepseek-ai/DeepSeek-R1-Distill-Qwen-7B) at runtime and uses trust_remote_code=True, which causes code and model artifacts to be fetched and potentially executed from the Hugging Face repo (e.g. https://huggingface.co/deepseek-ai/DeepSeek-R1-Distill-Qwen-7B) and these downloads are required for training/inference.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata