awq-quantization

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external calibration data, which represents a vulnerability surface for indirect prompt injection attacks. However, this data is necessary for the model quantization process and does not grant the agent excessive capabilities.
  • Ingestion points: Untrusted text data is ingested via the calib_data parameter in the model.quantize method calls within SKILL.md and references/advanced-usage.md.
  • Boundary markers: The provided code examples do not include explicit boundary markers or instructions to ignore embedded prompts within the calibration data.
  • Capability inventory: The skill's capabilities are limited to model quantization, weight saving, and basic text generation; it does not possess system-level write access, arbitrary command execution, or network exfiltration capabilities linked to the processed data.
  • Sanitization: No explicit sanitization or filtering of the calibration input strings is implemented in the provided instructional snippets.
  • [SAFE]: All external software dependencies and installation instructions utilize official registries (PyPI) and trusted organization repositories, such as those belonging to PyTorch. The usage of recognized libraries like autoawq and transformers is consistent with the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — awq-quantization