music-lab
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill orchestrates complex tasks by executing the
run.shentry points of other local skills using thesubprocess.runfunction. - Evidence is present in
converge.pyandpipeline.py, where the orchestrator calls scripts forcreate-music,review-music,prompt-lab,memory, andcreate-stems. - Command arguments are dynamically built from project parameters, file paths, and user-provided configuration values.
- [PROMPT_INJECTION]: The skill's pipeline is exposed to indirect prompt injection risks because it ingests and processes data from external sources and includes it in prompts for downstream LLM tasks.
- Ingestion points: In
pipeline.py, lore fragments are fetched from thememoryskill and musical reference data is retrieved from theconsume-musicskill. - Boundary markers: The skill does not employ specific delimiters or "ignore instructions" guardrails when interpolating this external data into the prompts sent to other tools like
create-storyandprompt-lab. - Capability inventory: The skill possesses broad capabilities, including the ability to execute shell commands, read and write to the local filesystem, and communicate with local network services for UI updates.
- Sanitization: External inputs are truncated to fixed character counts (e.g., 500 or 300 characters) but are not sanitized or escaped to neutralize potential instruction-based injection attacks.
Audit Metadata