music-generation

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The SKILL.md fragment describes a coherent, end-to-end local music-generation pipeline with music21-based composition, MIDI manipulation, and local rendering. No explicit exfiltration or credential theft is present. The highest-risk aspects are supply-chain/installation integrity (install.sh, pinned versions, hash checks) and the hard-coded, pipeline-specific rendering steps (program_change injection, channel assignments) that may complicate portability and reproducibility across environments. Overall, the risk is Moderate (with notable operational risk) but no clear malicious activity is detected in the fragment itself.

Confidence: 65%Severity: 50%
Audit Metadata
Analyzed At
Mar 1, 2026, 07:45 PM
Package URL
pkg:socket/skills-sh/cam10001110101%2Fclaude-skills-base%2Fmusic-generation%2F@0d3795589218f36d4040e0f34a7ea5ebac18a523