review-music

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external audio files and YouTube metadata which is subsequently processed and interpolated into LLM prompts.
  • Ingestion points: The skill accepts YouTube URLs in src/audio_loader.py and local audio files via the CLI in src/cli.py.
  • Boundary markers: Analysis prompts in src/analysis/llm_analyzer.py use Markdown headers to delimit sections, but do not employ strict escaping for untrusted content like transcribed lyrics.
  • Capability inventory: The skill utilizes network access for audio downloads and local file system writes for caching reviews and features.
  • Sanitization: There is no evidence of sanitization for track metadata (artist, title) or extracted lyrics before they are passed to the music theory reasoning engine.
  • [EXTERNAL_DOWNLOADS]: The src/audio_loader.py module facilitates the download of audio streams from YouTube using yt-dlp. YouTube is recognized as a well-known service for this purpose.
  • [COMMAND_EXECUTION]: The skill uses shell scripts (run.sh, sanity.sh) to manage its environment and execute MIR (Music Information Retrieval) tools. It leverages the Bash and Python tools to orchestrate feature extraction and batch processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — review-music