torchcode-pytorch-interview-practice

Warn

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the torch-judge package from the public PyPI registry. This package is niche and its contents are not verified by a known trusted organization.
  • [EXTERNAL_DOWNLOADS]: The skill points to external resources for source code and container images located at github.com/duoan/TorchCode and ghcr.io/duoan/torchcode, which are third-party repositories relative to the author's identified vendor profile.
  • [REMOTE_CODE_EXECUTION]: The skill uses the torch_judge library to perform automated correctness checks and gradient verification on code implementations. This requires executing external code provided by the package to evaluate local logic, which presents a security risk if the third-party package were to be compromised or malicious.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 28, 2026, 05:52 AM