scenario-audio

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for using curl to download audio assets. The download URL is obtained dynamically through the asset_download tool, which is the standard mechanism for retrieving generated media from the Scenario platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied prompts for text-to-audio generation. This represents an indirect prompt injection surface; however, the risk is minimal as the output is constrained to audio formats (MP3, WAV) and does not involve executable code or text-based instruction processing in downstream tasks.
  • [SAFE]: The skill refers to scenario-labs/skills, which is a resource owned by the skill author. Instructions to ask the user to install additional skills using npx are documented as part of the installation workflow and require explicit user action.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 07:46 AM
Security Audit — agent-trust-hub — scenario-audio