fine-tuning-serving-openpi

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download of the Physical Intelligence OpenPI repository and its associated model checkpoints from Google Cloud Storage (gs://openpi-assets). These resources originate from a well-known robotics AI research organization.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes natural language task descriptions as part of its observation input for robot policy inference.
  • Ingestion points: The prompt key within the observation dictionary, as seen in SKILL.md and references/remote-client-pattern.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the provided templates.
  • Capability inventory: The skill enables robot policy inference which generates control actions for physical or simulated robotic hardware.
  • Sanitization: No specific sanitization or filtering logic for the natural language prompts is included in the instructions.
  • [DYNAMIC_EXECUTION]: The PyTorch training workflow involves applying manual patches to the installed transformers library within the local virtual environment by copying modified source files from the cloned repository. This is a technical requirement for compatibility with the OpenPI model architecture.
  • [COMMAND_EXECUTION]: The instructions utilize the uv package manager and shell scripts (e.g., scripts/train.py, scripts/serve_policy.py) to manage dependencies and execute the training and inference pipelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — fine-tuning-serving-openpi