minimax-music-gen

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts untrusted user input for music descriptions, custom lyrics, and cover audio URLs, which are processed and interpolated directly into CLI commands.
  • Ingestion points: User prompts, custom lyrics strings, and external resource URLs parsed during the intent detection and creation phases in SKILL.md.
  • Boundary markers: Absent; user inputs are wrapped in double quotes within shell command templates without explicit delimiters or instructions to ignore embedded commands.
  • Capability inventory: Executes external shell commands via the mmx CLI tool for generation and audio players (mpv, ffplay, afplay) for local playback in SKILL.md.
  • Sanitization: Absent; the skill does not specify any sanitization or validation routines to escape shell metacharacters from user inputs.
  • [COMMAND_EXECUTION]: The skill requires executing various command-line operations to generate music and handle playback. This includes running the mmx binary with user-supplied arguments and invoking media players like mpv or ffplay. This is a core requirement of the skill's primary purpose but represents a capability surface that should be handled with caution by the underlying platform execution environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:59 AM
Security Audit — agent-trust-hub — minimax-music-gen