music-generator
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data that is subsequently passed to an external AI service (ElevenLabs).
- Ingestion points: The
--promptcommand-line argument and JSON files provided via the--compositionargument inscripts/generate_music.tsare ingestion points for untrusted data. - Boundary markers: There are no explicit delimiters or instructions provided to the downstream API to treat the input as untrusted data or to ignore embedded instructions.
- Capability inventory: The skill utilizes network access to communicate with the ElevenLabs API and has file system write access to save the resulting audio files.
- Sanitization: No sanitization, escaping, or validation of the text prompts is performed before they are interpolated into the API request body.
- [COMMAND_EXECUTION]: The skill's primary interface is a command-line script (
generate_music.ts) which requires the user to execute shell commands to generate music. - [EXTERNAL_DOWNLOADS]: The skill relies on external Node.js dependencies defined in
scripts/package.json(includingdotenv,ts-node, andtypescript) which are downloaded from the NPM registry during setup.
Audit Metadata