skills/grahama1970/agent-skills/hum/Gen Agent Trust Hub

hum

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and executes the third-party Docker image 'cherrymint/rvc_webui:rvc_boss' for voice model training tasks.
  • [REMOTE_CODE_EXECUTION]: The 'run.sh' script includes instructions for installing the 'uv' tool via a remote shell-piped command from 'astral.sh'.
  • [COMMAND_EXECUTION]: Uses the 'subprocess.run' module to orchestrate system utilities such as 'docker', 'ffmpeg', and 'pw-play' for media processing.
  • [COMMAND_EXECUTION]: Generates and runs dynamic Python scripts inside a Docker container using the 'python -c' interface within 'src/pipeline.py'.
  • [DATA_EXPOSURE]: Accesses and manages persona-related audio and metadata stored at '/mnt/storage12tb/media/personas/'.
  • [PROMPT_INJECTION]: Processes untrusted metadata from YouTube as part of the ingestion pipeline. Ingestion points: YouTube metadata is parsed in 'src/pipeline.py'. Boundary markers: None identified. Capability inventory: Execution of shell commands and filesystem write access. Sanitization: Content is slugified for use in file paths but stored directly in manifest files without rigorous validation.
Recommendations
  • HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — hum