consume-midi

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a dispatcher script (run.sh) to execute Python logic via uv run. This is a standard and safe way to manage dependencies and execution context in development environments.
  • [DATA_EXFILTRATION]: Communication with the back-end storage (ArangoDB via a memory daemon) is performed strictly over a local Unix Domain Socket (UDS) located at /run/user/{uid}/embry/memory.sock. The use of httpx is restricted to this local transport (base_url="http://localhost"), preventing data leakage to external networks.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes an ingestion surface that reads MIDI JSON metadata from user-specified directories. While this constitutes an external data ingestion point, the data is processed as structured JSON (musical keys, BPM, and MIDI note events) rather than natural language instructions, significantly limiting the risk of prompt-based subversion.
  • [SAFE]: No obfuscation, hardcoded credentials, or unauthorized persistence mechanisms were detected. The skill operates with the least privilege required to interact with the local MIDI library service.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — consume-midi