ai-music-generation

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the belt CLI via npx skills add belt-sh/cli and points to installation documentation hosted on GitHub at https://raw.githubusercontent.com/inference-sh/skills/refs/heads/main/cli-install.md.
  • [COMMAND_EXECUTION]: The skill uses the belt CLI to perform several tasks, including belt login for service authentication, belt app list for discovering models, and belt app run to execute music generation workloads on the inference.sh platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided inputs such as music prompts and lyrics, which are then passed to external AI models via the CLI tool. This creates an ingestion surface for untrusted data, though the risk is mitigated by the specialized nature of the CLI interface which is designed specifically for media generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 10:59 PM
Security Audit — agent-trust-hub — ai-music-generation