audio-music-generate

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a user-controlled prompt variable within a shell command: meitu audio-music-generate --prompt "<style/scene/mood>". This creates a vulnerability surface for command injection if the agent fails to escape shell-special characters in the user's input. Evidence chain: Ingestion point is the prompt argument in SKILL.md; Capability is the meitu binary execution; Boundary markers are absent in the command template; Sanitization instructions are missing.
  • [SAFE]: The access to sensitive files such as ~/.meitu/credentials.json and ~/.meitu/tool-registry.json is appropriate for this skill as it is authored by Meitu and requires these credentials to call its own OpenAPI.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 04:39 AM
Security Audit — agent-trust-hub — audio-music-generate