learn-artist
Fail
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The
enrich_taxonomyfunction inrun.shis vulnerable to command injection. It extracts tags and categories from YouTube metadata files (.info.json) and interpolates them directly into apython3 -cscript string. An attacker could craft a YouTube video with malicious tags that execute arbitrary code on the host system when processed by the skill.- [COMMAND_EXECUTION]: Thenzbgeek_fallbackfunction inrun.shcontains a shell injection vulnerability. It retrieves URLs from NZBGeek search results and passes them unquoted to a sub-shell command (bash "${nzbgeek_skill}" download "${nzb_url}" ...), allowing an attacker to execute commands via shell metacharacters in the URL.- [REMOTE_CODE_EXECUTION]: The skill pulls and executes a third-party Docker image (cherrymint/rvc_webui:rvc_boss) using the--gpus allflag and host volume mounts. Running unverified container images with access to host hardware and filesystems is a significant security risk.- [EXTERNAL_DOWNLOADS]: The skill automates the discovery and download of media files from YouTube and Usenet (via NZBGeek). Processing large volumes of external audio and metadata with complex tools like Demucs and RVC increases the attack surface for file-parsing and binary exploitation.- [DATA_EXFILTRATION]: The skill reads local environment configuration (.env) and exports metadata about the user's media library and training history to an external memory database (ArangoDB).
Recommendations
- AI detected serious security threats
Audit Metadata