axolotl
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documents the ability to fetch remote configuration files and examples from external sources.
- Evidence:
cli.utils.fetch.fetch_from_githubandcli.config.check_remote_configinreferences/api.mddescribe mechanisms to sync files from GitHub or query HTTPS URLs for YAML/JSON content. - [DYNAMIC_EXECUTION]: The skill describes a plugin and integration architecture that utilizes dynamic loading of Python modules.
- Evidence:
integrations.base.PluginManager.load_plugininreferences/api.mdimplements dynamic imports by splitting a string into a module and class name to instantiate extensions. - [COMMAND_EXECUTION]: The skill provides APIs for executing commands within specific cloud environments.
- Evidence:
cli.cloud.modal_.run_cmdinreferences/api.mdallows running commands inside a folder with Modal Volume integration. - [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted data from external datasets and remote configurations, creating a potential surface for indirect prompt injection.
- Ingestion points:
datasets(SKILL.md) andcheck_remote_config(references/api.md). - Boundary markers: The "Agent operating procedure" in
SKILL.mdinstructs the agent to pin down inputs, ask rather than guess values, and validate results. - Capability inventory: The skill enables model training (
cli.train.do_train), inference (cli.inference.do_inference), and cloud command execution via Modal (cli.cloud.modal_.run_cmd). - Sanitization: The skill relies on standard machine learning libraries (Hugging Face Datasets, Axolotl core) for processing inputs.
Audit Metadata