Back to skill

Security audit

Album Release Pipeline

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for album publishing, but it guides highly visible production actions like public uploads, radio deployment, service restarts, and social announcements without explicit confirmation or dry-run safeguards.

Install only if you intend an agent to help run a real album-release workflow against your own media providers, video host, radio host, and social accounts. Before use, add or require a preflight that lists all targets and public effects, defaults to dry-run, and asks for explicit confirmation before uploading, restarting services, premiering audio, or posting announcements.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This skill describes actions that can deploy audio to a live radio host, restart services, upload public media, and fan out announcements, but it does not present clear user-facing warnings or confirmation gates before those irreversible or externally visible operations. In a high-automation agent setting, that omission increases the risk of accidental production changes, unintended broadcasts, and premature public release even if the author’s intent is operational convenience rather than harm.

Static analysis

No suspicious patterns detected.