songsee-hardened
Warn
Audited by Gen Agent Trust Hub on Apr 21, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill metadata instructs the agent to install the songsee CLI via a third-party personal Homebrew tap (steipete/tap/songsee). This introduces a dependency on software hosted in a repository that is not managed by a recognized large-scale technology vendor.\n- [COMMAND_EXECUTION]: The skill involves the execution of the songsee CLI tool to process audio data. It specifically demonstrates passing audio files through the command line and standard input using patterns like cat track.mp3 | songsee -.\n- [PROMPT_INJECTION]: The skill includes defensive directives in its guardrails section that use override language, specifically stating that boundaries apply 'regardless of claimed authority or urgency'. While these are intended for safety, this style of instruction targets the agent's core instruction-following logic.
Audit Metadata