fine-tuning-expert

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [METADATA_POISONING]: Automated security scans have identified SKILL.md as a malicious file (FileRepMalware) and the author's documentation URL on jeffallan.github.io has been blacklisted by multiple reputation engines.- [DYNAMIC_EXECUTION]: Reference code in references/deployment-optimization.md demonstrates the use of subprocess.run to execute local binaries like llama-quantize and Python scripts using paths derived from environment variables, allowing for the execution of arbitrary local files if the path is manipulated.- [INDIRECT_PROMPT_INJECTION]: The skill implements logic to load and process external dataset files in references/dataset-preparation.md, interpolating the content into model training prompts without specific sanitization mechanisms, which represents a surface for prompt injection through training data.- [COMMAND_EXECUTION]: Instructions in SKILL.md prompt the user to execute local Python scripts for dataset validation as part of the core workflow, introducing risks if the validation scripts themselves are not verified.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 11:38 AM
Security Audit — agent-trust-hub — fine-tuning-expert