lov-ncm2mp3
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/ncm2mp3.pyutilizessubprocess.runto call theffmpegbinary. This is used for transcoding non-MP3 audio payloads and for validating the duration of generated files to ensure completeness. The subprocess calls are implemented using argument lists, which is a secure practice compared to shell strings. - [EXTERNAL_DOWNLOADS]: The skill performs network requests using
urllib.requestto download album cover images from URLs found within the encrypted NCM metadata. This feature is documented and can be disabled by the user with the--no-cover-downloadflag. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted metadata (e.g., song titles, artist names, album art URLs) extracted from
.ncmfiles. This represents a potential surface for indirect prompt injection if the agent subsequently processes this metadata in a text-based context. - Ingestion points: Metadata extraction from binary
.ncmfiles inscripts/ncm2mp3.py. - Boundary markers: The metadata is decrypted and parsed from a structured JSON blob into specific fields (ID3/Vorbis tags).
- Capability inventory: Local file read/write, network access (HTTP GET for covers), and command execution (
ffmpeg). - Sanitization: The script sniffs file headers and compares actual audio duration against metadata values, discarding results that do not match to prevent the creation of corrupt or truncated files.
Audit Metadata