llama-cpp
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches source code from a well-known repository to access necessary model conversion utilities.
- Evidence:
scripts/convert_lora_to_gguf.pyclones the officialllama.cpprepository from GitHub to access conversion scripts. - [COMMAND_EXECUTION]: The skill utilizes shell scripts and Python's subprocess module to interface with local CLI tools for model inference and management.
- Evidence: Execution of
llama-cli,llama-server,llama-quantize, andllama-export-loraacross several wrapper scripts. - [REMOTE_CODE_EXECUTION]: The skill installs a Python dependency from a downloaded source during its setup pipeline.
- Evidence:
scripts/convert_lora_to_gguf.pyexecutespip install -eon thegguf-pydirectory after cloning the llama.cpp repository. - [DYNAMIC_EXECUTION]: Python scripts dynamically assemble and execute commands based on local model path resolution and user-provided configuration.
- Evidence: The
runfunction inscripts/convert_lora_to_gguf.pyexecutes built command lists to perform model quantization and merging.
Audit Metadata