pymc-bayesian-modeling
Warn
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The reference file
references/advanced_workflows.mdprovides a recipe usingpickle.load()to restore saved model objects. Thepicklemodule is insecure by design, as it can be used to execute arbitrary code during deserialization. Loading a maliciously crafted pickle file can result in full system compromise. - [EXTERNAL_DOWNLOADS]: The
SKILL.mdfile contains instructions to install legitimate and well-known Python packages such aspymc,arviz,numpy, andmatplotlibvia the standardpippackage manager.
Audit Metadata