review-music
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external audio files and YouTube metadata which is subsequently processed and interpolated into LLM prompts.
- Ingestion points: The skill accepts YouTube URLs in
src/audio_loader.pyand local audio files via the CLI insrc/cli.py. - Boundary markers: Analysis prompts in
src/analysis/llm_analyzer.pyuse Markdown headers to delimit sections, but do not employ strict escaping for untrusted content like transcribed lyrics. - Capability inventory: The skill utilizes network access for audio downloads and local file system writes for caching reviews and features.
- Sanitization: There is no evidence of sanitization for track metadata (artist, title) or extracted lyrics before they are passed to the music theory reasoning engine.
- [EXTERNAL_DOWNLOADS]: The
src/audio_loader.pymodule facilitates the download of audio streams from YouTube usingyt-dlp. YouTube is recognized as a well-known service for this purpose. - [COMMAND_EXECUTION]: The skill uses shell scripts (
run.sh,sanity.sh) to manage its environment and execute MIR (Music Information Retrieval) tools. It leverages theBashandPythontools to orchestrate feature extraction and batch processing.
Audit Metadata