skills/bmz404/bmzskill/bmz-publish/Gen Agent Trust Hub

bmz-publish

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional Markdown content and does not include any executable scripts, binaries, or package dependencies. This absence of code eliminates standard attack vectors such as remote code execution or privilege escalation.
  • [SAFE]: No evidence of data exfiltration, obfuscation, or malicious instructions was found. The skill operates exclusively on user-provided music metadata to generate text-based suggestions.
  • [SAFE]: The skill processes untrusted user data such as lyrics and video descriptions, which is a common surface for indirect prompt injection. However, no specific vulnerabilities were found. 1. Ingestion points: user-provided lyrics and video descriptions; 2. Boundary markers: absent; 3. Capability inventory: text generation of titles and hooks; 4. Sanitization: none specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 02:27 AM
Security Audit — agent-trust-hub — bmz-publish