music-produce
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes
ffmpegandffprobeviachild_process.spawnwith theshell: falseoption. This ensures that arguments are passed directly to the executable without shell interpretation, effectively preventing command injection attacks. - [INDIRECT_PROMPT_INJECTION]: Ingestion points: The skill processes external audio files and JSON manifest data through scripts like
scripts/validate-delivery.ts. Boundary markers: There are no explicit delimiters or instructions to ignore embedded content within the processed files. Capability inventory: The skill has the ability to read, write, and delete files on the local system and perform complex audio processing. Sanitization: The scripts validate input types and escape path strings for FFmpeg concat files, but do not perform deep validation of external file content.
Audit Metadata