mlx-apple-silicon
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install
mlx,mlx-lm, andmlx-vlmvia standard package managers and provides examples of loading model weights from HuggingFace, which is typical for machine learning workflows. - [COMMAND_EXECUTION]: Provides examples of using local command-line tools for LLM generation, chat, and model conversion. These operations are restricted to the local development environment.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle user-supplied prompts and training data. Ingestion points: Processes external text via inference prompts and reads training data from local files (SKILL.md). Boundary markers: Demonstrates using
tokenizer.apply_chat_templateto manage chat boundaries (SKILL.md). Capability inventory: Includes fetching remote models, reading local datasets, and executing local binaries. Sanitization: The documentation focuses on framework usage; developers should implement appropriate sanitization for untrusted inputs in production.
Audit Metadata