llama-cpp

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches source code from a well-known repository to access necessary model conversion utilities.
  • Evidence: scripts/convert_lora_to_gguf.py clones the official llama.cpp repository from GitHub to access conversion scripts.
  • [COMMAND_EXECUTION]: The skill utilizes shell scripts and Python's subprocess module to interface with local CLI tools for model inference and management.
  • Evidence: Execution of llama-cli, llama-server, llama-quantize, and llama-export-lora across several wrapper scripts.
  • [REMOTE_CODE_EXECUTION]: The skill installs a Python dependency from a downloaded source during its setup pipeline.
  • Evidence: scripts/convert_lora_to_gguf.py executes pip install -e on the gguf-py directory after cloning the llama.cpp repository.
  • [DYNAMIC_EXECUTION]: Python scripts dynamically assemble and execute commands based on local model path resolution and user-provided configuration.
  • Evidence: The run function in scripts/convert_lora_to_gguf.py executes built command lists to perform model quantization and merging.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:20 AM
Security Audit — agent-trust-hub — llama-cpp