create-sound-design
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill dynamically modifies the system path to import modules from a sibling directory (
sfx-catalog). This pattern is observed increate_sound_design/memory_integration.pyandcreate_sound_design/sound_searcher.py. This relies on a specific local directory structure and could potentially load unintended code if the environment is compromised. - [INDIRECT_PROMPT_INJECTION]: The skill parses untrusted data from script files (JSON, Markdown) and storyboard files (YAML) to extract sound effect cues. This data influences the automated selection and placement of audio files.
- Ingestion points: Script and storyboard files parsed in
create_sound_design/scene_analyzer.py. - Boundary markers: None implemented; the parser extracts text descriptions directly.
- Capability inventory: File writing (manifest exports in
orchestrator.py), integration with sound libraries, and usage recording. - Sanitization: No explicit sanitization or filtering of the extracted text is performed before it is processed into cues.
Audit Metadata