music-production-master

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No malicious prompt injection patterns, role-play bypasses, or instructions to disregard safety guidelines were detected in the instructions or metadata.
  • [DATA_EXFILTRATION]: No attempts to access sensitive system files (e.g., credentials, SSH keys) or hardcoded secrets were found. The skill does not perform unauthorized network operations.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute remote scripts from untrusted sources. All operations are local and template-driven.
  • [COMMAND_EXECUTION]: The provided Bash scripts in the cli/ directory are benign walkthrough tools. They use standard shell practices (set -euo pipefail) and do not execute untrusted user-supplied input as commands.
  • [OBFUSCATION]: No Base64, hex-encoded content, zero-width characters, or other obfuscation techniques were found in any of the 16 analyzed files.
  • [INDIRECT_PROMPT_INJECTION]: While the skill uses external research tools (WebSearch) to gather industry information, it employs structured output formats and lacks high-privilege capabilities that could be exploited via malicious web content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 10:45 PM
Security Audit — agent-trust-hub — music-production-master