Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Fail4 providerslatest audit May 16, 2026
Independent checks from skills.sh's audit partners.
The skill provides tools for computer vision engineering, including dataset management, training configuration, and model optimization. However, it contains several security concerns related to the processing of untrusted files. It uses an unsafe method for loading PyTorch models that can result in arbitrary code execution, and its XML parsing logic is vulnerable to XML External Entity (XXE) attacks. Additionally, the ingestion of external dataset formats without isolation creates a surface for indirect prompt injection.
Detected behaviors
No alerts
No issues
5/7 files flagged