fairstack-model-compare

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation provides curl examples for performing model comparisons via terminal commands.
  • [EXTERNAL_DOWNLOADS]: The skill identifies the @fairstack/sdk Node.js package and the requests Python library as necessary dependencies for API interaction.
  • [DATA_EXFILTRATION]: User-provided text and prompts are transmitted to https://fairstack.ai to facilitate the model comparison functionality.
  • [PROMPT_INJECTION]: The skill ingests untrusted user prompts which are then processed by external AI models, creating a standard indirect prompt injection surface.
  • Ingestion points: User-provided prompt and text arguments within the comparison function calls.
  • Boundary markers: None identified in the instruction set to separate data from model instructions.
  • Capability inventory: Network egress capabilities via curl, requests, and the FairStack SDK to the fairstack.ai domain.
  • Sanitization: No input validation or content filtering is implemented within the skill definition.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 09:05 PM
Security Audit — agent-trust-hub — fairstack-model-compare