awq-quantization
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external calibration data, which represents a vulnerability surface for indirect prompt injection attacks. However, this data is necessary for the model quantization process and does not grant the agent excessive capabilities.
- Ingestion points: Untrusted text data is ingested via the
calib_dataparameter in themodel.quantizemethod calls withinSKILL.mdandreferences/advanced-usage.md. - Boundary markers: The provided code examples do not include explicit boundary markers or instructions to ignore embedded prompts within the calibration data.
- Capability inventory: The skill's capabilities are limited to model quantization, weight saving, and basic text generation; it does not possess system-level write access, arbitrary command execution, or network exfiltration capabilities linked to the processed data.
- Sanitization: No explicit sanitization or filtering of the calibration input strings is implemented in the provided instructional snippets.
- [SAFE]: All external software dependencies and installation instructions utilize official registries (PyPI) and trusted organization repositories, such as those belonging to PyTorch. The usage of recognized libraries like
autoawqandtransformersis consistent with the skill's stated purpose.
Audit Metadata