claude-music-cover

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to invoke local scripts such as music_engine.sh and preflight.sh to perform audio processing tasks.\n- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface where untrusted data (user-provided captions, lyrics, and file paths) is interpolated into shell commands. \n
  • Ingestion points: The --caption, --lyrics, and --src-audio parameters in the Bash command examples. \n
  • Boundary markers: None identified; inputs are passed directly as command-line arguments. \n
  • Capability inventory: The skill uses the Bash tool to execute subprocesses. \n
  • Sanitization: No explicit sanitization or escaping instructions are provided for the user-supplied strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 07:36 PM
Security Audit — agent-trust-hub — claude-music-cover