skills/sonilo-ai/skills/audio-ducking/Gen Agent Trust Hub

audio-ducking

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data via the voice_url and music_url parameters, which creates a potential surface for indirect prompt injection. If the processed media contains spoken instructions that are subsequently transcribed by the agent, they could influence the agent's behavior.
  • Ingestion points: The audio_ducking tool accepts remote HTTPS URLs through the voice_url and music_url parameters.
  • Boundary markers: There are no explicit instructions or delimiters used to ensure the agent ignores any commands embedded within the audio or video content.
  • Capability inventory: The skill possesses the ability to make network requests to the Sonilo API (api.sonilo.com) and write resulting files to the local filesystem (output_directory).
  • Sanitization: No sanitization or validation mechanisms are mentioned to filter or check the content of the external media files before they are processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:15 AM
Security Audit — agent-trust-hub — audio-ducking