music-lab

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill orchestrates complex tasks by executing the run.sh entry points of other local skills using the subprocess.run function.
  • Evidence is present in converge.py and pipeline.py, where the orchestrator calls scripts for create-music, review-music, prompt-lab, memory, and create-stems.
  • Command arguments are dynamically built from project parameters, file paths, and user-provided configuration values.
  • [PROMPT_INJECTION]: The skill's pipeline is exposed to indirect prompt injection risks because it ingests and processes data from external sources and includes it in prompts for downstream LLM tasks.
  • Ingestion points: In pipeline.py, lore fragments are fetched from the memory skill and musical reference data is retrieved from the consume-music skill.
  • Boundary markers: The skill does not employ specific delimiters or "ignore instructions" guardrails when interpolating this external data into the prompts sent to other tools like create-story and prompt-lab.
  • Capability inventory: The skill possesses broad capabilities, including the ability to execute shell commands, read and write to the local filesystem, and communicate with local network services for UI updates.
  • Sanitization: External inputs are truncated to fixed character counts (e.g., 500 or 300 characters) but are not sanitized or escaped to neutralize potential instruction-based injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — music-lab