llava
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions to clone the LLaVA repository from GitHub and install it using
pip install -e .. It also fetches pretrained model weights from the official repository on Hugging Face (liuhaotian/llava-v1.5-7b). These are standard operations for deploying this specific machine learning architecture. - [COMMAND_EXECUTION]: The instructions include various shell commands for running the CLI interface, launching a Gradio web server, and executing training scripts (e.g.,
bash scripts/v1_5/finetune.sh). These commands are intended for environment setup and model operation. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted data in the form of images and user-provided text queries through a Vision-Language Assistant.
- Ingestion points: The model ingests images via
Image.open()and text prompts via the CLI or Python API (SKILL.md). - Boundary markers: The skill utilizes standard conversation templates (
conv_templates["llava_v1"]), but does not include explicit security boundary markers or instructions for the model to ignore potential malicious content embedded within images. - Capability inventory: The skill environment includes capabilities for package installation (
pip), repository cloning (git), and shell script execution (bash,deepspeed) as documented in SKILL.md and training.md. - Sanitization: No specific sanitization or filtering logic is provided for the input images or user queries prior to model processing.
Audit Metadata