create-song

Warn

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill constructs shell commands for uv run using strings derived from user descriptions and track names. Malicious input provided in the description could potentially escape the intended command structure if the agent does not strictly follow the 'kebab-case slug' sanitization rule.
  • Evidence: SKILL.md (Step 1 and Step 6) describes using {track-name} in project folder creation and shell command execution contexts.
  • [REMOTE_CODE_EXECUTION]: The core mechanic of the skill involves the agent generating and running Python scripts at runtime. This process of executing dynamically created code is an inherently higher-risk operation, especially when combined with inputs from external sources.
  • Evidence: SKILL.md Step 6 (Parallel and Single-File Mode) instructs the agent to write and execute rendering scripts for individual song clips.
  • [REMOTE_CODE_EXECUTION]: The skill processes untrusted data from community-driven websites (ingestion points: WebFetch in SKILL.md Step 2) without explicit boundary markers to prevent the agent from obeying instructions embedded in the fetched data. This data influences the generation of scripts executed via uv run (capability inventory), and no sanitization is specified for the research results.
  • Evidence: SKILL.md Step 2 directs the agent to deep-dive into sites like Reddit and Hooktheory to extract composition details for the synthesis code.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 20, 2026, 04:21 PM
Security Audit — agent-trust-hub — create-song