mlflow
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process external data sources which may contain malicious instructions.\n
- Ingestion points: The agent is guided to use
mlflow.pyfunc.load_model(model_uri)inreferences/deployment.md, handle JSON inputs via Flask/FastAPIrequest.get_json(), and load data usingpd.read_csvorspark.read.parquet.\n - Boundary markers: There are no explicit instructions for the agent to use delimiters or ignore embedded instructions when processing these data sources.\n
- Capability inventory: The skill utilizes network operations (
mlflow server,requests.post, cloud deployments), file system operations (mlflow.log_artifact), and shell command execution viasubprocess.\n - Sanitization: No sanitization or validation of the processed data is specified in the operating procedures.\n- [DYNAMIC_EXECUTION]: The skill facilitates loading and executing machine learning models, which often involves deserialization of objects.\n
- Evidence: In
references/deployment.mdandreferences/model-registry.md, the skill demonstrates loading models from remote or local URIs usingmlflow.pyfunc.load_model. Because many MLflow model flavors usepickle, loading a model from an untrusted source could result in arbitrary code execution.\n- [COMMAND_EXECUTION]: The skill contains logic to execute shell commands to gather environment metadata.\n - Evidence: In
references/tracking.md, the skill includes a Python function usingsubprocess.check_output(['git', 'rev-parse', 'HEAD'])to retrieve Git commit hashes for experiment logging. While this is a common development task, it involves direct shell invocation.
Audit Metadata