ai-music-generation

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the 'belt' CLI tool from the inference.sh GitHub repository and provides links to official documentation. These resources are directly related to the skill's stated purpose of music generation.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to run the 'belt' CLI. The YAML frontmatter includes an 'allowed-tools' restriction (Bash(belt *)) which limits the agent to only executing commands that begin with 'belt', adhering to the principle of least privilege.
  • [CREDENTIALS_UNSAFE]: The documentation includes the 'belt login' command, which is a standard procedure for user authentication with the service. The skill does not contain hardcoded API keys or sensitive credentials.
  • [DATA_EXPOSURE]: No evidence of unauthorized access to sensitive local files or data exfiltration was detected. Network operations are directed towards the service provider's infrastructure (inference.sh).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 06:03 PM
Security Audit — agent-trust-hub — ai-music-generation