ai-local-model-ops
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes recipes that fetch installation scripts and container images from official, well-known services.
- Fetches the Ollama installation script from
https://ollama.com/install.shinassets/templates/ollama-setup-recipe.md. - References container images from
ghcr.io/open-webui/open-webuiandollama/ollamainassets/templates/openwebui-deployment-recipe.md. - [REMOTE_CODE_EXECUTION]: Provides instructions for executing a remote script via the shell to facilitate software installation.
- The
ollama-setup-recipe.mdfile suggests usingcurl -fsSL https://ollama.com/install.sh | shfor automated setup on macOS and Linux systems. - [COMMAND_EXECUTION]: The skill contains multiple templates (recipes) that provide shell commands for system configuration and tool deployment.
- Includes
systemctlcommands for managing background services anddocker run/docker composecommands for container orchestration. - Mentions the
ollama launchcommand inreferences/desktop-runtime-landscape.mdfor automated integration with coding tools and desktop applications. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes untrusted user requirements to generate executable configuration recipes.
- Ingestion points: User queries regarding local model setup and deployment constraints (identified in
SKILL.md). - Boundary markers: Explicit delimiters or 'ignore embedded instructions' warnings are not present in the generated templates.
- Capability inventory: The skill provides instructions for network operations (
curl), package installation, service management (systemctl), and container deployment (docker). - Sanitization: There is no evidence of automated sanitization or escaping of user-provided parameters within the output templates.
Audit Metadata