create-midi
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The
run.shscript facilitates the execution of internal Python scripts (compose.py,midi_utils.py,battle_score_packet.py) usinguv run. These commands are scoped to the skill's own directory and intended functionality. - [EXTERNAL_DOWNLOADS]: The
compose.pyscript makes an HTTP POST request to a local or configured proxy (SCILLM_API_BASE) for LLM-based music arrangement. This is a standard pattern for agent skills utilizing external models via a managed gateway. The default endpoint ishttp://localhost:4001/v1. - [CREDENTIALS_UNSAFE]: A default development API key (
sk-dev-proxy-123) is present incompose.pyfor theSCILLM_PROXY_KEY. However, this is documented as a development placeholder and the script prefers environment variables, which is consistent with standard development practices for local proxies. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data (lyrics, MIDI fragments, and arrangement notes) to construct an LLM prompt. While this presents an injection surface (Category 8), the risk is low as the data is musical in nature and the output is strictly validated against a JSON schema (
piano-roll-spec.json) before being used for MIDI generation. Structural validation is also performed on battle score packets to prevent improper claims. - [DATA_EXFILTRATION]: There is no evidence of sensitive file access (e.g., SSH keys, AWS credentials) being sent over the network. The network activity is restricted to the LLM proxy for composition tasks.
Audit Metadata