timesfm-forecasting

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/check_system.py uses subprocess.run to execute sysctl on macOS platforms. This is performed solely to retrieve the physical RAM size for system requirement validation before loading large models.
  • [DYNAMIC_EXECUTION]: The script scripts/check_system.py uses importlib.import_module to verify if required packages like timesfm and torch are installed. This is a standard practice for preflight checking and does not involve executing untrusted input.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download model weights from Hugging Face using official repository IDs such as google/timesfm-2.5-200m-pytorch. These resources are provided by a known, reputable research organization.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided CSV files in scripts/forecast_csv.py. While it ingests external data, it performs strictly numerical forecasting operations. There is no logic that executes or interprets the content of these files as instructions for the agent or the shell.
  • [DATA_EXPOSURE]: No hardcoded credentials or sensitive file paths were detected. The model weights are stored in the standard Hugging Face cache directory (~/.cache/huggingface), which is standard behavior for machine learning tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — timesfm-forecasting