sound-effects
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data (prompts and video content) that could contain adversarial instructions targeting the agent.
- Ingestion points: The prompt, video_path, and video_url parameters in the tools serve as entry points for untrusted data.
- Boundary markers: There are no instructions or delimiters provided to help the agent distinguish between data and instructions.
- Capability inventory: The skill enables network communication with api.sonilo.com and file writes to the local system.
- Sanitization: The instructions do not specify any sanitization or validation for input prompts or media content.
- [UNVERIFIABLE_DEPENDENCIES]: The skill documentation describes the use of the sonilo and sonilo-cli packages, which are official libraries provided by the vendor for interacting with their service.
Audit Metadata