programmatic-music
Warn
Audited by Snyk on Aug 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Outsider-authored free text can be ingested via runtime calls to
music21.converter.parse(...)when given attacker-controlled strings/URLs (e.g.,converter.parse('https://example.com/x.krn')or XML/tinyNotation text), and the skill explicitly supports importing “existing material” (scores/audio) through parsing/conversion.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata