speculative-decoding

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent or user to fetch source code from third-party GitHub repositories not included in the trusted vendor list.
  • Evidence: git clone https://github.com/FasterDecoding/Medusa found in SKILL.md and references/medusa.md.
  • Evidence: git clone https://github.com/hao-ai-lab/LookaheadDecoding found in SKILL.md and references/lookahead.md.
  • [REMOTE_CODE_EXECUTION]: The skill proceeds to install and execute the code downloaded from external sources, which could allow for the execution of arbitrary code if the repositories are compromised.
  • Evidence: The command pip install -e . is executed within the cloned directories for both Medusa and LookaheadDecoding in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for processing untrusted user prompts through various LLM inference techniques without utilizing boundary markers or sanitization logic.
  • Ingestion points: User-supplied prompt variables are interpolated into generation functions in SKILL.md (e.g., target_model.generate, model.medusa_generate, lookahead.generate).
  • Boundary markers: Absent. No delimiters or instructions are provided to the agent to treat the prompt as data rather than instructions.
  • Capability inventory: The skill utilizes torch, transformers, and vllm for model execution, and performs shell operations via git and pip as documented in SKILL.md.
  • Sanitization: Absent. The skill passes the raw prompt directly to the inference engine.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — speculative-decoding