llama-factory

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONREMOTE_CODE_EXECUTION
Full Analysis
  • [SAFE]: The skill serves as a legitimate technical documentation assistant for the LLaMA-Factory framework, and its instructions are consistent with the primary purpose of helping users fine-tune machine learning models.
  • [COMMAND_EXECUTION]: The instructions involve running standard machine learning CLI tools such as llamafactory-cli, torchrun, accelerate, and deepspeed. These commands are expected for the task of model training and evaluation.
  • [PRIVILEGE_ESCALATION]: The skill documents the use of sudo specifically for system administration tasks such as installing or uninstalling CUDA drivers. This is a standard requirement for configuring hardware-accelerated machine learning environments.
  • [REMOTE_CODE_EXECUTION]: The documentation references the trust_remote_code parameter, which is a standard feature of the Hugging Face transformers and modelscope libraries. While this parameter allows for the execution of code from remote model repositories, it is presented here as a configurable argument for the user rather than an automated exploit.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — llama-factory