sound-fx
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were identified. The skill's behavior matches its stated purpose.
- [EXTERNAL_DOWNLOADS]: Fetches generated audio assets from Google Cloud Storage, which is recognized as a well-known and reliable service.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-defined text prompts to generate audio. The vulnerability surface is documented as follows:
- Ingestion points: The prompt parameter in scripts/sfx.py and SKILL.md triggers.
- Boundary markers: Not explicitly implemented in the prompt string before transmission to the API.
- Capability inventory: Network access for API communication and file downloads; filesystem access for managing API keys and saving audio files.
- Sanitization: Not present; the prompt is passed directly to the API, but the resulting output is binary audio, posing no direct threat to the agent context.
Audit Metadata