mlflow

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process external data sources which may contain malicious instructions.\n
  • Ingestion points: The agent is guided to use mlflow.pyfunc.load_model(model_uri) in references/deployment.md, handle JSON inputs via Flask/FastAPI request.get_json(), and load data using pd.read_csv or spark.read.parquet.\n
  • Boundary markers: There are no explicit instructions for the agent to use delimiters or ignore embedded instructions when processing these data sources.\n
  • Capability inventory: The skill utilizes network operations (mlflow server, requests.post, cloud deployments), file system operations (mlflow.log_artifact), and shell command execution via subprocess.\n
  • Sanitization: No sanitization or validation of the processed data is specified in the operating procedures.\n- [DYNAMIC_EXECUTION]: The skill facilitates loading and executing machine learning models, which often involves deserialization of objects.\n
  • Evidence: In references/deployment.md and references/model-registry.md, the skill demonstrates loading models from remote or local URIs using mlflow.pyfunc.load_model. Because many MLflow model flavors use pickle, loading a model from an untrusted source could result in arbitrary code execution.\n- [COMMAND_EXECUTION]: The skill contains logic to execute shell commands to gather environment metadata.\n
  • Evidence: In references/tracking.md, the skill includes a Python function using subprocess.check_output(['git', 'rev-parse', 'HEAD']) to retrieve Git commit hashes for experiment logging. While this is a common development task, it involves direct shell invocation.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — mlflow