elevenlabs-voice-changer
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of audio URLs and JSON parameters passed to the
beltCLI. This is a functional requirement but creates a potential surface for indirect prompt injection. - Ingestion points:
audioURL and JSON configuration inSKILL.md. - Boundary markers: None.
- Capability inventory: Shell execution of the
beltCLI. - Sanitization: No sanitization is described in the skill instructions.
- [EXTERNAL_DOWNLOADS]: The skill references the
belt-sh/clipackage and related resources from theinference-shorganization to provide necessary functionality.
Audit Metadata