weights-and-biases
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides comprehensive guides and code snippets for using the Weights & Biases (W&B) platform. All external URLs and resources point to the official W&B domain (wandb.ai) or the official GitHub repository (github.com/wandb/wandb).
- [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to download and process external machine learning artifacts, which establishes a potential surface for indirect prompt injection if the agent reads data from an untrusted source.
- Ingestion points: In
references/artifacts.md, therun.use_artifact()andartifact.download()methods are used to retrieve datasets and models from the W&B server for subsequent processing by the agent. - Boundary markers: No specific delimiters or safety instructions are defined to guide the agent in distinguishing between data and potential instructions within the downloaded artifact files.
- Capability inventory: The skill possesses the capability to write files to the local disk (
torch.save,wandb.save) and communicate with W&B cloud infrastructure viawandb.logandwandb.log_artifact. - Sanitization: There are no content sanitization or validation mechanisms implemented to verify the integrity of the data stored within external artifacts before it is processed by the agent.
Audit Metadata