consume-music

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs dynamic code loading in memory_integration.py to incorporate functionality from a separate module. It uses importlib.util to locate and execute a Python script (taxonomy.py) from a computed path relative to the skill directory. This pattern allows for the execution of code that is not statically defined within the primary skill package.
  • Evidence: memory_integration.py (lines 44-51) uses spec_from_file_location and exec_module to load a module from _SKILLS_DIR / "taxonomy" / "taxonomy.py".
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted metadata (video titles and artist names) from external sources and integrates it into the agent's memory system without adequate sanitization or boundary markers.
  • Ingestion points: ingest_bridge.py reads data from ~/.pi/ingest-yt-history/history.jsonl, which contains YouTube watch history including user-controlled or attacker-influenced video titles.
  • Boundary markers: The skill does not implement delimiters or safety instructions when processing or storing these titles to prevent the agent from following instructions embedded in the data.
  • Capability inventory: The skill has access to Bash and Python tools, performs file write operations (e.g., to registry.json and notes.jsonl), and interacts with the MemoryClient for data storage and retrieval.
  • Sanitization: No security-focused sanitization or filtering is performed on the ingested content beyond basic formatting via regular expressions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — consume-music