music-discover
Pass
Audited by Gen Agent Trust Hub on Feb 27, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains a functional tool usage restriction ("Never use the webFetch tool") which is a benign instructional constraint. It also processes external music data (artist names, track titles), representing a surface for indirect prompt injection, but this is inherent to its primary purpose and carries minimal risk given the restrictive tool set.\n- Ingestion points: Results from
spotifyUser,spotifyArtists, and built-in web search.\n- Boundary markers: None defined for external content.\n- Capability inventory: Limited to Spotify playback control and playlist management.\n- Sanitization: Not specified, which is common for metadata-focused skills.
Audit Metadata