pytorch-lightning
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides standardized templates and guides for building data pipelines (e.g.,
scripts/template_datamodule.py) that ingest external datasets for model training and validation. This creates a surface for indirect prompt injection, as malicious instructions embedded within the processed data could attempt to influence the agent's behavior during the training or evaluation process. - Ingestion points: Data processing methods such as
prepare_dataandsetupinLightningDataModule, along with batch processing hooks inLightningModule(training_step,validation_step,test_step). - Boundary markers: The provided code templates do not include specific delimiters or instructions to the model to ignore embedded commands or distinguish between data and instructions.
- Capability inventory: The skill possesses the capability to write to the local file system (via
ModelCheckpoint), communicate with external logging services (Weights & Biases, MLflow, Comet), and execute shell commands (as theBashtool is allowed in the skill configuration). - Sanitization: The provided instructions and boilerplate scripts do not implement explicit sanitization, filtering, or validation of the input data to mitigate potential injection attacks.
Audit Metadata