llama-cpp

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions involve standard operations for model inference, including running 'llama-cli' and 'llama-server'. It also provides documentation for building the llama.cpp project from source using CMake and make, and installing it via common package managers like Homebrew and Winget.
  • [EXTERNAL_DOWNLOADS]: The skill fetches model files and repository information from the Hugging Face Hub and clones source code from the official llama.cpp GitHub repository. These activities target established, well-known platforms and organizations within the AI development community.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface related to the processing of external data from the Hugging Face Hub API and web pages.
  • Ingestion points: Hugging Face repository search results, local-app page content, and the tree API JSON responses (SKILL.md, references/hub-discovery.md).
  • Boundary markers: Not explicitly defined in the instructions for separating external model metadata from the agent's internal logic.
  • Capability inventory: Subprocess execution for hardware checks (nvidia-smi), inference commands, and model conversion (references/advanced-usage.md, references/quantization.md).
  • Sanitization: Not specified for the data retrieved from external repositories.
  • [NO_CODE]: The skill package does not contain any executable code, scripts, or binaries; it is composed entirely of instructional Markdown files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 01:34 PM