generative-music-composer

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes functions for reading and preprocessing MIDI files in references/midi-reference.md and references/markov-music.md. Processing these external binary formats constitutes a data ingestion point. Without explicit boundary markers or sanitization of the musical data, this presents a surface for indirect prompt injection if the resulting sequences are subsequently interpreted by an AI agent.
  • [EXTERNAL_DOWNLOADS]: The skill references the mido and midiutil Python packages for handling MIDI data and file generation. These are widely recognized and standard libraries within the music technology community.
  • [COMMAND_EXECUTION]: The provided code snippets perform file system operations, specifically writing MIDI data to disk using Python's open() function and the save() method in references/midi-reference.md. While necessary for the skill's purpose of music generation, this involves interaction with the host file system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — generative-music-composer