sound-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to use firecrawl_search and WebFetch to retrieve external documentation and platform guidelines. This represents an indirect prompt injection surface. 1. Ingestion points: mcp__firecrawl__firecrawl_search and WebFetch tools described in the 'MCP Integrations' section of SKILL.md. 2. Boundary markers: Not present. 3. Capability inventory: Bash (specifically allowing python, node, npm, and ffmpeg), Write, and Edit tools. 4. Sanitization: Not present.
  • [SAFE]: The C++ and Swift code examples in references/implementations.md are standard, domain-appropriate algorithms for HRTF spatialization, Ambisonic encoding/decoding, and procedural synthesis.
  • [SAFE]: The skill's external dependencies and tool usage, such as ElevenLabs for sound effect generation and fetching documentation from established vendors like Apple and Android, align with its primary purpose and follow best practices for the domain.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:42 AM
Security Audit — agent-trust-hub — sound-engineer