learn-voice

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill orchestrates a complex machine learning pipeline using bash and docker exec. User-provided artist names are processed through a slugify function that restricts input to alphanumeric characters and hyphens. This ensures that when these names are used in file paths or interpolated into Python script strings within the Docker container, they cannot trigger shell or code injection.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the cherrymint/rvc_webui:rvc_boss Docker image to provide the necessary dependencies for RVC training. It also downloads audio content from YouTube via the sibling discover-music skill. These downloads are central to the skill's primary function and target well-known community resources.
  • [DATA_EXFILTRATION]: The script sends training status and progress updates to a local Task Monitor API at http://localhost:8765. This communication is restricted to the local host and is used for workspace-internal telemetry.
  • [REMOTE_CODE_EXECUTION]: The skill manages a remote Docker image for computation. The execution is scoped to the training of voice models and uses fixed command patterns that are not influenced by un-sanitized external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — learn-voice