model-merging

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and installs mergekit from Arcee AI's official GitHub repository. It also recommends standard machine learning libraries from well-known registries like PyPI.
  • [COMMAND_EXECUTION]: Provides instructions and Python scripts to execute the mergekit-yaml CLI tool via subprocess.run. This is used for the intended purpose of merging model weights locally.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external models and the generation of text for benchmarking purposes.
  • Ingestion points: Model weights and identifiers are loaded from HuggingFace Hub or local paths (e.g., SKILL.md, references/coefficient-tuning.md).
  • Boundary markers: No specific prompt delimiters are implemented in the example scripts.
  • Capability inventory: Includes model loading, text generation, local command execution (mergekit-yaml), and network access for model synchronization.
  • Sanitization: Standard evaluation metrics like ROUGE and BERTScore are used to compare outputs, but no specific input sanitization is present for model names.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — model-merging