create-music
Warn
Audited by Snyk on Mar 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's required setup/workflow (e.g., scripts/rvc_setup.sh invoked by SKILL.md/run.sh) clones the public RVC WebUI GitHub repo and downloads pretrained files from Hugging Face, and the Dockerfile.musicgen pulls a public image (mrloldev/musicgen), so it fetches and executes untrusted third‑party content as part of normal operation which could contain instructions that alter agent/tool behavior.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 1.00). The skill's rvc_setup.sh explicitly runs git clone https://github.com/RVC-Project/Retrieval-based-Voice-Conversion-WebUI.git and downloads pretrained weights from https://huggingface.co/lj1995/VoiceConversionWebUI/resolve/main/rmvpe.pt (and hubert_base.pt), and those fetched repositories/files are executed/used at runtime by the rvc_infer.sh / rvc_train.sh pipelines, so remote code is fetched and run as a required dependency.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata