ai-music-and-sound

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its data processing instructions.
  • Ingestion points: The instructions in SKILL.md and references/scope-and-connections.md state that the agent must read external files including the 'brand-profile' and the 'video/asset' being scored.
  • Boundary markers: No specific delimiters or instructions are provided to separate these external inputs from the agent's core instructions, making it possible for content in those files to influence the agent's behavior.
  • Capability inventory: While the provided files do not include executable scripts, the skill's instructions direct the agent to perform analysis and advisory tasks. In a default environment where tools are not restricted in the frontmatter, the agent may have access to tools that could be abused via injection.
  • Sanitization: No input validation, escaping, or filtering of the external content is described.
  • [PROMPT_INJECTION]: The skill presents hypothetical legal and industry information (e.g., settlements dated late 2025/2026) as 'verified' facts within a future-dated persona. This metadata poisoning could lead to the agent providing inaccurate information about the current real-world legal status of AI music tools.
  • [NO_CODE]: The analyzed skill package consists entirely of markdown-based instructions, frameworks, and JSON evaluation data. No executable code or binary files were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 02:27 PM
Security Audit — agent-trust-hub — ai-music-and-sound