peft-fine-tuning
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes training data from external datasets by interpolating instruction and response fields into prompts during the fine-tuning process.
- Ingestion points: The
tokenizefunction inSKILL.mdand theformat_chatfunction inreferences/advanced-usage.mdprocess user-controlled instruction and response data. - Boundary markers: Employs standard instruction/response delimiters (e.g.,
### Instruction:,### Response:) to structure training data. - Capability inventory: The skill utilizes
Trainer.trainfor model training,save_pretrainedfor local file writes, andpush_to_hubfor network uploads to Hugging Face. - Sanitization: Data is interpolated directly into template strings without explicit sanitization, which is standard practice for LLM training but represents a surface for indirect instructions.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for obtaining and installing necessary machine learning libraries and source code.
- The skill provides guidance on installing standard ecosystem packages such as
peft,transformers,accelerate,bitsandbytes, anddatasetsfrom official package registries. - The troubleshooting guide includes instructions to clone the
bitsandbytessource code from its official GitHub repository for custom compilation, which is a common practice in specialized machine learning environments.
Audit Metadata