consume-music
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs dynamic code loading in
memory_integration.pyto incorporate functionality from a separate module. It usesimportlib.utilto locate and execute a Python script (taxonomy.py) from a computed path relative to the skill directory. This pattern allows for the execution of code that is not statically defined within the primary skill package. - Evidence:
memory_integration.py(lines 44-51) usesspec_from_file_locationandexec_moduleto load a module from_SKILLS_DIR / "taxonomy" / "taxonomy.py". - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted metadata (video titles and artist names) from external sources and integrates it into the agent's memory system without adequate sanitization or boundary markers.
- Ingestion points:
ingest_bridge.pyreads data from~/.pi/ingest-yt-history/history.jsonl, which contains YouTube watch history including user-controlled or attacker-influenced video titles. - Boundary markers: The skill does not implement delimiters or safety instructions when processing or storing these titles to prevent the agent from following instructions embedded in the data.
- Capability inventory: The skill has access to
BashandPythontools, performs file write operations (e.g., toregistry.jsonandnotes.jsonl), and interacts with theMemoryClientfor data storage and retrieval. - Sanitization: No security-focused sanitization or filtering is performed on the ingested content beyond basic formatting via regular expressions.
Audit Metadata