ai-music-audio

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The audio watermarking implementation in references/patterns.md uses child_process.spawn to run an embedded Python script. This represents a dynamic execution surface used for cross-language interoperability, implemented safely without using a shell.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input for music and speech generation. Ingestion points: Prompt and text fields in references/patterns.md. Boundary markers: None in implementation patterns; recommended in references/sharp_edges.md. Capability inventory: Subprocess execution and network requests in references/patterns.md. Sanitization: Absent in base code; remediation provided in references/sharp_edges.md.
  • [COMMAND_EXECUTION]: The skill uses child_process.spawn to interface with specialized Python audio tools. The implementation avoids shell injection by passing arguments as an array rather than a single string.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:03 PM
Security Audit — agent-trust-hub — ai-music-audio