music-generator

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data that is subsequently passed to an external AI service (ElevenLabs).
  • Ingestion points: The --prompt command-line argument and JSON files provided via the --composition argument in scripts/generate_music.ts are ingestion points for untrusted data.
  • Boundary markers: There are no explicit delimiters or instructions provided to the downstream API to treat the input as untrusted data or to ignore embedded instructions.
  • Capability inventory: The skill utilizes network access to communicate with the ElevenLabs API and has file system write access to save the resulting audio files.
  • Sanitization: No sanitization, escaping, or validation of the text prompts is performed before they are interpolated into the API request body.
  • [COMMAND_EXECUTION]: The skill's primary interface is a command-line script (generate_music.ts) which requires the user to execute shell commands to generate music.
  • [EXTERNAL_DOWNLOADS]: The skill relies on external Node.js dependencies defined in scripts/package.json (including dotenv, ts-node, and typescript) which are downloaded from the NPM registry during setup.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 10:20 AM
Security Audit — agent-trust-hub — music-generator