music
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFENO_CODEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns or behaviors were identified. The skill consists entirely of documentation and examples.
- [NO_CODE]: The skill package does not include any executable code, scripts, or binary files; it only contains markdown documentation.
- [EXTERNAL_DOWNLOADS]: The skill references the vendor's official API domain (am.runware.ai) for audio generation and hosting. Users can also provide external URLs for source audio when creating covers, which is a core feature.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its processing of user-supplied style descriptions and lyrics.
- Ingestion points: positivePrompt and settings.lyrics in SKILL.md.
- Boundary markers: No specific boundary markers are used to isolate user content.
- Capability inventory: The skill performs network-based audio generation through the Runware API.
- Sanitization: No sanitization of user input is documented within the skill instructions.
Audit Metadata