axolotl

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents the ability to fetch remote configuration files and examples from external sources.
  • Evidence: cli.utils.fetch.fetch_from_github and cli.config.check_remote_config in references/api.md describe mechanisms to sync files from GitHub or query HTTPS URLs for YAML/JSON content.
  • [DYNAMIC_EXECUTION]: The skill describes a plugin and integration architecture that utilizes dynamic loading of Python modules.
  • Evidence: integrations.base.PluginManager.load_plugin in references/api.md implements dynamic imports by splitting a string into a module and class name to instantiate extensions.
  • [COMMAND_EXECUTION]: The skill provides APIs for executing commands within specific cloud environments.
  • Evidence: cli.cloud.modal_.run_cmd in references/api.md allows running commands inside a folder with Modal Volume integration.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted data from external datasets and remote configurations, creating a potential surface for indirect prompt injection.
  • Ingestion points: datasets (SKILL.md) and check_remote_config (references/api.md).
  • Boundary markers: The "Agent operating procedure" in SKILL.md instructs the agent to pin down inputs, ask rather than guess values, and validate results.
  • Capability inventory: The skill enables model training (cli.train.do_train), inference (cli.inference.do_inference), and cloud command execution via Modal (cli.cloud.modal_.run_cmd).
  • Sanitization: The skill relies on standard machine learning libraries (Hugging Face Datasets, Axolotl core) for processing inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — axolotl