voice-enforcement

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions in SKILL.md reference a non-standard command-line utility voice-scorer for scoring and analyzing documents. While this appears to be a project-specific tool associated with the 'organvm-iv-taxis' ecosystem, the binary itself is not provided within the skill, and users should verify the source and integrity of such external tools before execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process prose-heavy documents (doc.md) to evaluate them against the 'Voice Constitution'. This creates a surface where malicious instructions embedded in the analyzed text could potentially influence agent behavior.
  • Ingestion points: Input documents provided for scoring via the voice-scorer CLI or direct agent review in SKILL.md.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' commands when the agent processes the external document content.
  • Capability inventory: The agent is empowered to review, diff, and potentially edit documents based on the provided constitution, which involves significant processing of untrusted content.
  • Sanitization: There are no explicit requirements for sanitizing or filtering input text before it is analyzed for voice compliance.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — voice-enforcement