hqq-quantization
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a technical guide for HQQ quantization, providing legitimate code snippets for model optimization using PyTorch, HuggingFace Transformers, and vLLM. No malicious patterns such as prompt injection, data exfiltration, or obfuscation were detected.
- [EXTERNAL_DOWNLOADS]: The skill references several external resources, including the official HQQ GitHub repository (github.com/mobiusml/hqq) and HuggingFace models (huggingface.co/mobiuslabsgmbh). These are well-known services and trusted sources within the machine learning community.
- [COMMAND_EXECUTION]: The skill provides installation commands (
pip install hqq) and usage examples for standard ML tools. These commands are necessary for the primary purpose of the skill and do not involve suspicious execution patterns or privilege escalation. - [DATA_EXFILTRATION]: No evidence of unauthorized data access or exfiltration was found. Mentions of saving models locally or pushing them to the HuggingFace Hub are standard practices for model deployment and management.
- [INDIRECT_PROMPT_INJECTION]: While the skill includes examples that process user prompts (e.g., via Gradio or LangChain), these are standard LLM inference workflows. The skill does not possess high-risk capabilities that would make it vulnerable to exploitation via indirect injection in this context.
Audit Metadata