music-compose

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as music customisation packs and reference analysis documents, which could theoretically contain malicious instructions designed to influence agent behavior. \n
  • Ingestion points: Customisation packs (referenced in SKILL.md) and reference analysis (referenced in references/reference-analysis.md). \n
  • Boundary markers: The skill defines a clear precedence hierarchy where explicit user instructions and approved decisions override pack guidance. \n
  • Capability inventory: Local Node.js scripts handle file read/write and validation tasks for MIDI and composition data. \n
  • Sanitization: Artifacts are validated against an expected schema using the scripts/validate-composition.ts tool. \n- [COMMAND_EXECUTION]: The skill uses local Node.js scripts (inspect-midi.ts, transpose-midi.ts) to perform deterministic music theory calculations and MIDI file manipulations. These scripts run in the local environment and are restricted to specific music-related operations. \n- [EXTERNAL_DOWNLOADS]: The skill relies on external Node.js packages (@tonejs/midi, tonal) installed via npm. These are well-known, versioned libraries from the official registry used for standard music processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 09:26 PM
Security Audit — agent-trust-hub — music-compose