harmix-music-search
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: Hardcoded API key
v8mWxAGAFTEFcU9NYGGhDWWbzYXS5efound inSKILL.md,references/prompt-search.md,references/video-search.md, andscripts/video_search.py. Exposing functional credentials in skill source code allows for unauthorized usage and potential quota exhaustion. - [COMMAND_EXECUTION]: The script
scripts/video_search.pyinvokessubprocess.runto executeffmpegandffprobe. While the implementation uses list-based arguments rather than a raw shell string, it performs operations on user-supplied file paths to extract video frames, which constitutes a local command execution surface. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and displays data from the Harmix API (track titles, artists, and URLs). There are no boundary markers or instructions for the agent to treat this external content as untrusted data, creating a vulnerability surface where a compromised or malicious API response could influence the agent's behavior.
Recommendations
- AI detected serious security threats
Audit Metadata