acestep
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill includes explicit security instructions for the agent to avoid reading or displaying API keys in plain text to prevent accidental leakage in chat logs or console output.
- [SAFE]: The
acestep.shutility script implements credential masking for theapi_keyfield in its configuration listing and reset commands, ensuring secrets are not printed to the terminal during routine administration. - [SAFE]: The shell script utilizes
jqwith proper argument-based interpolation (--argand--argjson) to construct API payloads, effectively mitigating risks of command injection or JSON structure manipulation from user-supplied input. - [SAFE]: All network operations, documentation links, and code references target official infrastructure belonging to the ACE-Step vendor (acemusic.ai and GitHub), with no evidence of typosquatting or redirection to untrusted third-party services.
Audit Metadata