musickit
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides search functionality that incorporates user-provided text into queries.
- Ingestion points: The
termparameter in thesearchCatalogfunction (SKILL.md) and thesearchTextstate in theMusicSearchViewcomponent (references/musickit-patterns.md). - Boundary markers: The search string is passed directly to the
MusicCatalogSearchRequestwithout boundary markers or instructions to ignore embedded commands. - Capability inventory: The skill snippets are limited to MusicKit API calls and UI updates; they do not include dangerous capabilities such as arbitrary command execution, file system modifications, or non-API network requests.
- Sanitization: The input is used directly without sanitization or validation.
- [EXTERNAL_DOWNLOADS]: The skill references an external documentation source for framework information.
- Source:
https://sosumi.ai/documentation/(Multiple links in SKILL.md) - Context: The skill provides links to an unofficial or mirror documentation site for developer guidance on MusicKit APIs.
Audit Metadata