pufferlib
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the official PufferLib source code on GitHub and its published packages on PyPI. These references include specific, immutable commit hashes and SHA-256 digests for provenance verification, following best practices for software supply chain security.
- [CREDENTIALS_UNSAFE]: The skill includes a dedicated
secret_key_pathsfunction that scans configuration data for sensitive keys such asapi_key,token, andsecret. The validation logic proactively rejects plans or metadata containing potential credentials to prevent accidental exposure. - [DATA_EXFILTRATION]: Filesystem access is strictly controlled through a
resolve_local_pathhelper that prevents directory traversal and symlink-following. This ensures that file operations are confined to authorized project directories and prevents access to sensitive system files. - [REMOTE_CODE_EXECUTION]: The
inspect_checkpoint.pyutility provides a secure method for analyzing model files. It calculates cryptographic hashes and inspects file headers for format detection while explicitly avoiding the use oftorch.loadorpickle.load, which effectively mitigates the risk of executing malicious code embedded in untrusted model checkpoints. - [DYNAMIC_EXECUTION]: The training template generator (
train_template.py) is designed for safety; it builds command-line argument previews for human review and explicitly avoids executing the generated commands, maintaining human-in-the-loop oversight for all training operations.
Audit Metadata