music-discover

Pass

Audited by Gen Agent Trust Hub on Feb 27, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains a functional tool usage restriction ("Never use the webFetch tool") which is a benign instructional constraint. It also processes external music data (artist names, track titles), representing a surface for indirect prompt injection, but this is inherent to its primary purpose and carries minimal risk given the restrictive tool set.\n- Ingestion points: Results from spotifyUser, spotifyArtists, and built-in web search.\n- Boundary markers: None defined for external content.\n- Capability inventory: Limited to Spotify playback control and playlist management.\n- Sanitization: Not specified, which is common for metadata-focused skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 27, 2026, 12:13 PM