skills/runware/runware-skills/music/Gen Agent Trust Hub

music

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFENO_CODEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns or behaviors were identified. The skill consists entirely of documentation and examples.
  • [NO_CODE]: The skill package does not include any executable code, scripts, or binary files; it only contains markdown documentation.
  • [EXTERNAL_DOWNLOADS]: The skill references the vendor's official API domain (am.runware.ai) for audio generation and hosting. Users can also provide external URLs for source audio when creating covers, which is a core feature.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its processing of user-supplied style descriptions and lyrics.
  • Ingestion points: positivePrompt and settings.lyrics in SKILL.md.
  • Boundary markers: No specific boundary markers are used to isolate user content.
  • Capability inventory: The skill performs network-based audio generation through the Runware API.
  • Sanitization: No sanitization of user input is documented within the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 04:08 PM
Security Audit — agent-trust-hub — music