elevenlabs-dubbing
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the
belt-sh/clipackage for installation and links to setup documentation hosted on the official GitHub repository for the inference.sh service. - [COMMAND_EXECUTION]: The skill provides instructions for executing the
beltCLI tool, including login procedures and running dubbing applications with JSON-formatted inputs. Theallowed-toolsfrontmatter correctly scopes these operations to thebeltcommand. - [INDIRECT_PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection as it ingests untrusted media via the
audioURL field. However, the risk is minimal as the content is processed as binary audio/video data by an external translation engine rather than being interpreted as natural language instructions for the agent context.
Audit Metadata