create-intent-map

Warn

Audited by Snyk on Mar 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly downloads and loads third‑party models/code from the public HuggingFace hub (e.g., AutoModelForCausalLM.from_pretrained(DEFAULT_BASE_MODEL) with HF_TOKEN referenced in SKILL.md/run.sh and trust_remote_code=True) and also calls external LLM services (scillm/Chutes via call_chutes/ScillmClient and Ollama endpoints) whose outputs are parsed and used in variation generation, evaluation, and reward signals—untrusted content that can materially alter training/inference behavior.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill repeatedly calls transformers.from_pretrained with model IDs (e.g., deepseek-ai/DeepSeek-R1-Distill-Qwen-7B) at runtime and uses trust_remote_code=True, which causes code and model artifacts to be fetched and potentially executed from the Hugging Face repo (e.g. https://huggingface.co/deepseek-ai/DeepSeek-R1-Distill-Qwen-7B) and these downloads are required for training/inference.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:36 AM
Issues
2
Security Audit — snyk — create-intent-map