audiocraft-audio-generation
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes instructions to download software and model checkpoints from well-known and reputable sources, including PyPI, GitHub (specifically the facebookresearch organization), and HuggingFace.
- Evidence includes installation commands such as
pip install git+https://github.com/facebookresearch/audiocraft.gitand model loading calls likeMusicGen.get_pretrained('facebook/musicgen-small'). - [INDIRECT_PROMPT_INJECTION]: The skill processes natural language descriptions provided by users to generate music and sound effects, creating a potential surface for indirect injection attacks.
- Ingestion points: User-supplied strings passed to the
descriptionsargument in generation methods acrossSKILL.mdand reference files. - Boundary markers: None identified in the provided examples.
- Capability inventory: The skill performs file system operations (saving
.wavfiles viatorchaudio.save) and network operations (fetching pre-trained models from HuggingFace/GitHub). - Sanitization: No explicit sanitization or filtering of text prompts is implemented in the provided code snippets.
Audit Metadata