regressor-lab

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs subprocess.run in several scripts (e.g., benchmark.py, pipeline.py, and bridge.py) to execute internal Python modules and interact with the create-regressor skill. All subprocess calls are implemented securely by passing arguments as lists, which effectively prevents shell injection attacks.- [DATA_EXPOSURE]: The collection script (scripts/collect.py) is designed to read training data from specific absolute paths on the host system, such as /mnt/storage12tb/extractor_corpus/results. This access to external directories is documented and necessary for the skill's primary function of building machine learning models from existing local document extraction profiles.- [SAFE]: The skill implements path validation (bridge.py) to ensure files exist before processing and maintains a clear separation between the UI and backend processing using a Python-based bridge. No unauthorized network activity or credential exposure was detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — regressor-lab