llama-factory
Warn
Audited by Gen Agent Trust Hub on Feb 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- EXTERNAL_DOWNLOADS (MEDIUM): The skill lists 'llmtuner' as a required dependency in SKILL.md. This package is listed without a version constraint and originates from a repository/organization not recognized in the trusted external sources list, requiring verification before installation.
- PROMPT_INJECTION (LOW): The skill ingests external content from readthedocs.io, creating an indirect prompt injection surface. The risk is assessed as LOW because the skill serves an informational purpose and lacks capabilities for high-privilege side effects. 1. Ingestion points: references/*.md (markdown documentation files). 2. Boundary markers: None identified. 3. Capability inventory: Local documentation display and guidance via the 'view' tool. 4. Sanitization: No sanitization of documentation content is mentioned.
Audit Metadata