sfx-catalog

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill utilizes joblib.load() in src/content_classifier.py and src/audio_analyzer.py to import classification models from the skill's data/ folder. joblib utilizes the Python pickle module, which is insecure because it can execute arbitrary code during the deserialization process. This presents a risk where a compromised or malicious model file could execute code on the host machine.
  • [COMMAND_EXECUTION]: The src/memory_bridge.py script executes local bash scripts via subprocess.run(). It specifically calls the run.sh script from an external memory skill. While argument passing is structured to prevent basic shell injection, the reliance on spawning subprocesses to communicate between components increases the potential impact of local privilege escalation or environment tampering.
  • [PROMPT_INJECTION]: There is a potential surface for indirect prompt injection during the audio cataloging process.
  • Ingestion points: src/audio_analyzer.py reads filenames from the filesystem in catalog_directory (line 120), which are then used to generate keywords and descriptions.
  • Boundary markers: The system lacks delimiters or protective instructions to distinguish between metadata content and system instructions when storing this data in the memory system.
  • Capability inventory: The skill has filesystem access and subprocess execution capabilities (as seen in src/memory_bridge.py).
  • Sanitization: Filenames are processed in src/metadata_generator.py without sanitization. If these filenames contain malicious instructions, they will be stored in the memory system and could potentially influence the behavior of other skills that use that memory as context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:36 AM
Security Audit — agent-trust-hub — sfx-catalog