ml-property-predict-scd

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The wrapper scripts run_ct_scd_qm9.py and run_ct_scd_matbench.py use the subprocess module to orchestrate the training process.
  • They implement logic to automatically restart the script within the required scd-agent Conda environment using conda run if the current environment is incorrect.
  • The scripts construct command-line arguments for the train.py entry point, incorporating configuration paths and user-specified parameters like dataset properties or job identifiers.
  • [EXTERNAL_DOWNLOADS]: Several templates automate the acquisition of foundation model weights from the Hugging Face Hub.
  • templates/extract_embeddings.py and templates/train_lightweight_head.py utilize huggingface_hub.hf_hub_download to fetch the last.ckpt files.
  • These downloads target the author's public repositories (Ty-Perez/ct-scd-pcq and Ty-Perez/ct-scd-amp).
  • [SAFE]: Static analysis detections for eval() are false positives related to the PyTorch library.
  • The code uses model.eval(), backbone.eval(), and head.eval(), which are standard PyTorch methods for toggling a model's operational state to evaluation mode. These do not invoke the Python eval() built-in for code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 04:47 PM