tao-train-sparse4d

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFEPROMPT_INJECTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: Documentation in BENCHMARK.md and skill-card.md contains self-referential safety claims such as "Security: 100%" and "Overall verdict: PASS". These statements are designed to target security analyzers to influence the final risk assessment.
  • [REMOTE_CODE_EXECUTION]: The skill processes annotation and metadata files in the Python pickle (.pkl) format during model training and evaluation. Since these files are supplied by external datasets, the underlying use of pickle.load for deserialization represents a potential dynamic execution vulnerability surface.
  • [COMMAND_EXECUTION]: The skill automates complex machine learning workflows through the execution of sparse4d and annotations CLI tools, which operate on local file systems and system hardware.
  • [EXTERNAL_DOWNLOADS]: Integration with the Weights & Biases (wandb) platform is included for experiment tracking. This involves network connections to an established external service for data logging and visualization.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 05:48 PM
Security Audit — agent-trust-hub — tao-train-sparse4d