music-produce

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes ffmpeg and ffprobe via child_process.spawn with the shell: false option. This ensures that arguments are passed directly to the executable without shell interpretation, effectively preventing command injection attacks.
  • [INDIRECT_PROMPT_INJECTION]: Ingestion points: The skill processes external audio files and JSON manifest data through scripts like scripts/validate-delivery.ts. Boundary markers: There are no explicit delimiters or instructions to ignore embedded content within the processed files. Capability inventory: The skill has the ability to read, write, and delete files on the local system and perform complex audio processing. Sanitization: The scripts validate input types and escape path strings for FFmpeg concat files, but do not perform deep validation of external file content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 09:26 PM
Security Audit — agent-trust-hub — music-produce