create-sound-design

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill dynamically modifies the system path to import modules from a sibling directory (sfx-catalog). This pattern is observed in create_sound_design/memory_integration.py and create_sound_design/sound_searcher.py. This relies on a specific local directory structure and could potentially load unintended code if the environment is compromised.
  • [INDIRECT_PROMPT_INJECTION]: The skill parses untrusted data from script files (JSON, Markdown) and storyboard files (YAML) to extract sound effect cues. This data influences the automated selection and placement of audio files.
  • Ingestion points: Script and storyboard files parsed in create_sound_design/scene_analyzer.py.
  • Boundary markers: None implemented; the parser extracts text descriptions directly.
  • Capability inventory: File writing (manifest exports in orchestrator.py), integration with sound libraries, and usage recording.
  • Sanitization: No explicit sanitization or filtering of the extracted text is performed before it is processed into cues.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — create-sound-design