custom-blocks

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • Dynamic Module Loading: The skill describes the use of importlib to load local Python files during the packaging process. \n
  • Context: Importing a module executes its top-level code. The skill documentation proactively informs the user that the module will be executed and advises running it only on trusted files, which is a standard security practice for development tools.\n- Remote Code Execution Surface: The skill provides instructions for enabling the trust_remote_code flag in the generated repository config. \n
  • Context: This flag is a core feature of the diffusers library that allows users to share and load custom pipeline components. The documentation explicitly highlights its use, ensuring transparency for both the developer and the end consumer.\n- Indirect Prompt Injection Surface: The tool processes local Python source code as its primary input. \n
  • Ingestion points: The --block_module_name parameter identifies local files for processing in SKILL.md. \n
  • Boundary markers: The process utilizes the Python ast module to scan for specific class definitions, providing a structural check before the file is imported. \n
  • Capability inventory: The CLI tool performs local file reads and writes to the current working directory. \n
  • Sanitization: The tool relies on AST parsing to identify valid block subclasses, though the execution of the code itself is managed by the standard Python import mechanism.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 11:53 AM