zai-tts
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes the
uvxcommand, which downloads and executes thezai-ttspackage from an external registry (likely PyPI) at runtime. This introduces a dependency on an unverified third-party package. - [COMMAND_EXECUTION]: The skill performs shell command execution using
uvx zai-tts. It constructs commands that include user-supplied data, which can lead to unintended execution if the input is not handled correctly. - [INDIRECT_PROMPT_INJECTION]: The skill instructions provide a template for shell commands where user-supplied messages are interpolated:
uvx zai-tts -t "{msg}". This creates a command injection surface if the{msg}content is sourced from untrusted data (e.g., a summarized web page). - Ingestion points: The
{msg}parameter in the usage examples inSKILL.md. - Boundary markers: The
{msg}variable is enclosed in double quotes, but there is no instruction for the agent to escape shell-metacharacters (e.g.,;,&,|,$(...)) within that input. - Capability inventory: The skill has the capability to execute shell commands and write files to a temporary directory.
- Sanitization: No sanitization or validation logic is defined to prevent an attacker from escaping the quotes and executing arbitrary shell commands.
Audit Metadata