create-midi

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The run.sh script facilitates the execution of internal Python scripts (compose.py, midi_utils.py, battle_score_packet.py) using uv run. These commands are scoped to the skill's own directory and intended functionality.
  • [EXTERNAL_DOWNLOADS]: The compose.py script makes an HTTP POST request to a local or configured proxy (SCILLM_API_BASE) for LLM-based music arrangement. This is a standard pattern for agent skills utilizing external models via a managed gateway. The default endpoint is http://localhost:4001/v1.
  • [CREDENTIALS_UNSAFE]: A default development API key (sk-dev-proxy-123) is present in compose.py for the SCILLM_PROXY_KEY. However, this is documented as a development placeholder and the script prefers environment variables, which is consistent with standard development practices for local proxies.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (lyrics, MIDI fragments, and arrangement notes) to construct an LLM prompt. While this presents an injection surface (Category 8), the risk is low as the data is musical in nature and the output is strictly validated against a JSON schema (piano-roll-spec.json) before being used for MIDI generation. Structural validation is also performed on battle score packets to prevent improper claims.
  • [DATA_EXFILTRATION]: There is no evidence of sensitive file access (e.g., SSH keys, AWS credentials) being sent over the network. The network activity is restricted to the LLM proxy for composition tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — create-midi