fine-tuning-expert
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [METADATA_POISONING]: Automated security scans have identified
SKILL.mdas a malicious file (FileRepMalware) and the author's documentation URL onjeffallan.github.iohas been blacklisted by multiple reputation engines.- [DYNAMIC_EXECUTION]: Reference code inreferences/deployment-optimization.mddemonstrates the use ofsubprocess.runto execute local binaries likellama-quantizeand Python scripts using paths derived from environment variables, allowing for the execution of arbitrary local files if the path is manipulated.- [INDIRECT_PROMPT_INJECTION]: The skill implements logic to load and process external dataset files inreferences/dataset-preparation.md, interpolating the content into model training prompts without specific sanitization mechanisms, which represents a surface for prompt injection through training data.- [COMMAND_EXECUTION]: Instructions inSKILL.mdprompt the user to execute local Python scripts for dataset validation as part of the core workflow, introducing risks if the validation scripts themselves are not verified.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata