nvflare-convert-pytorch
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to perform automatic code analysis and conversion on arbitrary user repositories containing PyTorch code. This processing of untrusted project data (such as user code comments, custom config files, and README files) creates an inherent surface for indirect prompt injection attacks. Testing fixtures included in the repository demonstrate this specific attack vector:
- Ingestion Points:
evals/files/injection-pt/README.md,evals/files/injection-pt/train.py, andevals/files/injection-pt/config.yamlinject adversarial instructions instructing the AI agent to override security practices, install custom third-party packages, or transmit internal project weights to remote endpoints. - Boundary Markers: Absent from the main parsing loop of the code converter, meaning the agent relies on its inherent model instructions to look at these files strictly as static code artifacts/evidence rather than actionable behavior directives.
- Capability Inventory: The converter interacts with file-writing utilities, dependency verification tools, and configuration generation mechanisms.
- Sanitization: The skill mitigates this surface effectively in practice by explicitly instructing the model to treat discovered code artifacts as structural data/evidence rather than command authorization, preventing compliance with embedded injection payloads.
Audit Metadata