harmix-music-search

Fail

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: Hardcoded API key v8mWxAGAFTEFcU9NYGGhDWWbzYXS5e found in SKILL.md, references/prompt-search.md, references/video-search.md, and scripts/video_search.py. Exposing functional credentials in skill source code allows for unauthorized usage and potential quota exhaustion.
  • [COMMAND_EXECUTION]: The script scripts/video_search.py invokes subprocess.run to execute ffmpeg and ffprobe. While the implementation uses list-based arguments rather than a raw shell string, it performs operations on user-supplied file paths to extract video frames, which constitutes a local command execution surface.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and displays data from the Harmix API (track titles, artists, and URLs). There are no boundary markers or instructions for the agent to treat this external content as untrusted data, creating a vulnerability surface where a compromised or malicious API response could influence the agent's behavior.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 23, 2026, 04:47 AM
Security Audit — agent-trust-hub — harmix-music-search