weights-and-biases

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides comprehensive guides and code snippets for using the Weights & Biases (W&B) platform. All external URLs and resources point to the official W&B domain (wandb.ai) or the official GitHub repository (github.com/wandb/wandb).
  • [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to download and process external machine learning artifacts, which establishes a potential surface for indirect prompt injection if the agent reads data from an untrusted source.
  • Ingestion points: In references/artifacts.md, the run.use_artifact() and artifact.download() methods are used to retrieve datasets and models from the W&B server for subsequent processing by the agent.
  • Boundary markers: No specific delimiters or safety instructions are defined to guide the agent in distinguishing between data and potential instructions within the downloaded artifact files.
  • Capability inventory: The skill possesses the capability to write files to the local disk (torch.save, wandb.save) and communicate with W&B cloud infrastructure via wandb.log and wandb.log_artifact.
  • Sanitization: There are no content sanitization or validation mechanisms implemented to verify the integrity of the data stored within external artifacts before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — weights-and-biases