mlx-apple-silicon

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install mlx, mlx-lm, and mlx-vlm via standard package managers and provides examples of loading model weights from HuggingFace, which is typical for machine learning workflows.
  • [COMMAND_EXECUTION]: Provides examples of using local command-line tools for LLM generation, chat, and model conversion. These operations are restricted to the local development environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle user-supplied prompts and training data. Ingestion points: Processes external text via inference prompts and reads training data from local files (SKILL.md). Boundary markers: Demonstrates using tokenizer.apply_chat_template to manage chat boundaries (SKILL.md). Capability inventory: Includes fetching remote models, reading local datasets, and executing local binaries. Sanitization: The documentation focuses on framework usage; developers should implement appropriate sanitization for untrusted inputs in production.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:57 PM