ai-music-generation

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: References installation instructions for the vendor's command-line tool hosted on GitHub.
  • [COMMAND_EXECUTION]: Utilizes the infsh CLI to execute music generation models and list available applications.
  • [DATA_EXFILTRATION]: Transmits user-provided prompts and lyrics to the inference.sh platform for song generation, which is the primary function of the skill.
  • [PROMPT_INJECTION]: Features an indirect injection surface where user-supplied prompts and lyrics are used as arguments for CLI commands. Ingestion points: User-provided strings for prompts and lyrics; Boundary markers: Uses JSON structure for command inputs; Capability inventory: Employs the Bash tool to run vendor-specific commands; Sanitization: Relies on standard JSON encapsulation for command arguments.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 09:07 PM