llama-factory
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONREMOTE_CODE_EXECUTION
Full Analysis
- [SAFE]: The skill serves as a legitimate technical documentation assistant for the LLaMA-Factory framework, and its instructions are consistent with the primary purpose of helping users fine-tune machine learning models.
- [COMMAND_EXECUTION]: The instructions involve running standard machine learning CLI tools such as
llamafactory-cli,torchrun,accelerate, anddeepspeed. These commands are expected for the task of model training and evaluation. - [PRIVILEGE_ESCALATION]: The skill documents the use of
sudospecifically for system administration tasks such as installing or uninstalling CUDA drivers. This is a standard requirement for configuring hardware-accelerated machine learning environments. - [REMOTE_CODE_EXECUTION]: The documentation references the
trust_remote_codeparameter, which is a standard feature of the Hugging Facetransformersandmodelscopelibraries. While this parameter allows for the execution of code from remote model repositories, it is presented here as a configurable argument for the user rather than an automated exploit.
Audit Metadata