soundtrack

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes instructions to fetch AI-generated music from OpenRouter (openrouter.ai). This is a well-known service used for accessing AI models, and the process uses standard environment variables for API key management.- [COMMAND_EXECUTION]: The synchronization script (sync-check.mjs) uses ffmpeg and ffprobe via execFileSync to analyze video and audio. This is a secure way to handle external media processing tools within the skill's workflow.- [DYNAMIC_EXECUTION]: A Python script is used as a one-liner to parse streaming JSON data from the music API. This script specifically handles data processing (base64 decoding) to save audio content to a local file.- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied media files and JSON cue data to perform its synchronization checks. While this constitutes an external data ingestion surface, the risk is minimal as the data is used for quantitative analysis (loudness and timing) rather than being interpreted as instructions for the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:31 PM
Security Audit — agent-trust-hub — soundtrack