llava

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to clone the LLaVA repository from GitHub and install it using pip install -e .. It also fetches pretrained model weights from the official repository on Hugging Face (liuhaotian/llava-v1.5-7b). These are standard operations for deploying this specific machine learning architecture.
  • [COMMAND_EXECUTION]: The instructions include various shell commands for running the CLI interface, launching a Gradio web server, and executing training scripts (e.g., bash scripts/v1_5/finetune.sh). These commands are intended for environment setup and model operation.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted data in the form of images and user-provided text queries through a Vision-Language Assistant.
  • Ingestion points: The model ingests images via Image.open() and text prompts via the CLI or Python API (SKILL.md).
  • Boundary markers: The skill utilizes standard conversation templates (conv_templates["llava_v1"]), but does not include explicit security boundary markers or instructions for the model to ignore potential malicious content embedded within images.
  • Capability inventory: The skill environment includes capabilities for package installation (pip), repository cloning (git), and shell script execution (bash, deepspeed) as documented in SKILL.md and training.md.
  • Sanitization: No specific sanitization or filtering logic is provided for the input images or user queries prior to model processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — llava