huggingface-trackio

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the trackio library from official package registries. The library is maintained by Hugging Face, an established service in the machine learning ecosystem.
  • [DATA_EXFILTRATION]: Provides functionality to synchronize training data with Hugging Face Spaces and dispatch alerts to external Slack or Discord webhooks. These are documented features of the integrated services. The instructions clarify that auto-created Spaces are public by default unless specific privacy flags are used.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes an autonomous workflow where an agent polls for and interprets training alerts and metrics to guide its next actions, such as adjusting hyperparameters or restarting runs. \n
  • Ingestion points: Alert text and metric data are ingested via the trackio CLI tool, as detailed in references/retrieving_metrics.md and references/alerts.md. \n
  • Boundary markers: The Anti-Patterns section in SKILL.md provides instructional guidance against treating tool responses or logs as trusted instructions, though no technical delimitation is present in the CLI output formats. \n
  • Capability inventory: The agent is encouraged to use these data points to manage training processes, terminate runs, and relaunch experiments with modified configurations. \n
  • Sanitization: No specific validation, filtering, or sanitization of the training log content is mentioned before the data is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:52 AM
Security Audit — agent-trust-hub — huggingface-trackio