learn-artist

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The enrich_taxonomy function in run.sh is vulnerable to command injection. It extracts tags and categories from YouTube metadata files (.info.json) and interpolates them directly into a python3 -c script string. An attacker could craft a YouTube video with malicious tags that execute arbitrary code on the host system when processed by the skill.- [COMMAND_EXECUTION]: The nzbgeek_fallback function in run.sh contains a shell injection vulnerability. It retrieves URLs from NZBGeek search results and passes them unquoted to a sub-shell command (bash "${nzbgeek_skill}" download "${nzb_url}" ...), allowing an attacker to execute commands via shell metacharacters in the URL.- [REMOTE_CODE_EXECUTION]: The skill pulls and executes a third-party Docker image (cherrymint/rvc_webui:rvc_boss) using the --gpus all flag and host volume mounts. Running unverified container images with access to host hardware and filesystems is a significant security risk.- [EXTERNAL_DOWNLOADS]: The skill automates the discovery and download of media files from YouTube and Usenet (via NZBGeek). Processing large volumes of external audio and metadata with complex tools like Demucs and RVC increases the attack surface for file-parsing and binary exploitation.- [DATA_EXFILTRATION]: The skill reads local environment configuration (.env) and exports metadata about the user's media library and training history to an external memory database (ArangoDB).
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 17, 2026, 06:36 AM
Security Audit — agent-trust-hub — learn-artist