skills/firecrawl/openclaw/songsee/Gen Agent Trust Hub

songsee

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's metadata includes installation instructions using the Homebrew package manager, targeting the steipete/tap/songsee formula hosted on GitHub. This is a standard method for distributing macOS and Linux command-line utilities.
  • [COMMAND_EXECUTION]: The skill provides various usage examples for the songsee binary, including processing local audio files, using pipes (stdin), and specifying output parameters. These commands are consistent with the tool's primary purpose of audio visualization.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data in the form of audio files (e.g., MP3, WAV) to generate visual output.
  • Ingestion points: The songsee tool reads audio data from local file paths or standard input as shown in SKILL.md.
  • Boundary markers: Not applicable as the tool generates graphical spectrograms rather than processing natural language instructions.
  • Capability inventory: The skill utilizes the songsee binary and potentially ffmpeg for audio decoding.
  • Sanitization: Standard shell argument handling is assumed for the CLI tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:54 PM
Security Audit — agent-trust-hub — songsee