music-evaluate
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes scripts like
inspect-audio.tsto perform technical analysis on audio files. These scripts call system utilities (ffprobe,ffmpeg) using a secure wrapper inrun-command.tsthat employschild_process.spawnwithshell: false. This approach effectively prevents command injection vulnerabilities by ensuring arguments are not interpreted by a shell. - [CREDENTIALS_UNSAFE]: The
preflight.tsscript checks for the existence of theREPLICATE_API_TOKENenvironment variable to determine if optional semantic benchmarking is available. The script only logs whether the token is "available" or "MISSING" and does not print, store, or transmit the secret value itself. - [DATA_EXPOSURE]: Data handling is restricted to reading local JSON evidence and metadata files. The skill instructions and scripts do not contain any network exfiltration patterns, and the technical QC is performed locally using standard audio processing tools.
- [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data (music artifacts and metadata), it contains explicit instructions to avoid inventing observations and uses deterministic scripts for technical verification. The capability surface is focused on structured reporting, which minimizes the risk of indirect prompt injection affecting the agent's behavior.
Audit Metadata