voice-enforcement
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions in
SKILL.mdreference a non-standard command-line utilityvoice-scorerfor scoring and analyzing documents. While this appears to be a project-specific tool associated with the 'organvm-iv-taxis' ecosystem, the binary itself is not provided within the skill, and users should verify the source and integrity of such external tools before execution. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process prose-heavy documents (
doc.md) to evaluate them against the 'Voice Constitution'. This creates a surface where malicious instructions embedded in the analyzed text could potentially influence agent behavior. - Ingestion points: Input documents provided for scoring via the
voice-scorerCLI or direct agent review inSKILL.md. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' commands when the agent processes the external document content.
- Capability inventory: The agent is empowered to review, diff, and potentially edit documents based on the provided constitution, which involves significant processing of untrusted content.
- Sanitization: There are no explicit requirements for sanitizing or filtering input text before it is analyzed for voice compliance.
Audit Metadata