skills/ace-step/ace-step-1.5/acestep/Gen Agent Trust Hub

acestep

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill includes explicit security instructions for the agent to avoid reading or displaying API keys in plain text to prevent accidental leakage in chat logs or console output.
  • [SAFE]: The acestep.sh utility script implements credential masking for the api_key field in its configuration listing and reset commands, ensuring secrets are not printed to the terminal during routine administration.
  • [SAFE]: The shell script utilizes jq with proper argument-based interpolation (--arg and --argjson) to construct API payloads, effectively mitigating risks of command injection or JSON structure manipulation from user-supplied input.
  • [SAFE]: All network operations, documentation links, and code references target official infrastructure belonging to the ACE-Step vendor (acemusic.ai and GitHub), with no evidence of typosquatting or redirection to untrusted third-party services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:25 PM
Security Audit — agent-trust-hub — acestep