discover-music
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The run.sh script downloads the uv tool installation script from https://astral.sh/uv/install.sh. This is a legitimate installation step for a well-known Python environment management tool.
- [REMOTE_CODE_EXECUTION]: The skill executes the downloaded uv installer by piping it to the shell in run.sh. As this originates from a reputable source (Astral), it is considered safe installation behavior.
- [COMMAND_EXECUTION]: The src/cli_youtube.py script uses subprocess.run to invoke the run.sh scripts of other local skills (ingest-youtube and create-stems) and executes the demucs module for audio separation.
- [DATA_EXFILTRATION]: The skill makes network requests to MusicBrainz and ListenBrainz to search for music and retrieve recommendations. These operations are core to the skill's documented functionality and involve non-sensitive metadata.
- [SAFE]: An email address (grahama@me.com) is hardcoded for the MusicBrainz User-Agent contact field in src/musicbrainz_client.py and sanity.sh. This is a policy requirement of the MusicBrainz API and is not a credential.
- [SAFE]: The skill processes structured taste profile data from ~/.pi/ingest-yt-history/profile.json (Ingestion point). While it lacks specific boundary markers and possesses capabilities for subprocess execution and file writing (Capability inventory), the risk is minimal given the data is sourced internally from the Horus agent ecosystem.
Audit Metadata