skills/aahl/skills/zai-tts/Gen Agent Trust Hub

zai-tts

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the uvx command, which downloads and executes the zai-tts package from an external registry (likely PyPI) at runtime. This introduces a dependency on an unverified third-party package.
  • [COMMAND_EXECUTION]: The skill performs shell command execution using uvx zai-tts. It constructs commands that include user-supplied data, which can lead to unintended execution if the input is not handled correctly.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions provide a template for shell commands where user-supplied messages are interpolated: uvx zai-tts -t "{msg}". This creates a command injection surface if the {msg} content is sourced from untrusted data (e.g., a summarized web page).
  • Ingestion points: The {msg} parameter in the usage examples in SKILL.md.
  • Boundary markers: The {msg} variable is enclosed in double quotes, but there is no instruction for the agent to escape shell-metacharacters (e.g., ;, &, |, $(...)) within that input.
  • Capability inventory: The skill has the capability to execute shell commands and write files to a temporary directory.
  • Sanitization: No sanitization or validation logic is defined to prevent an attacker from escaping the quotes and executing arbitrary shell commands.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 03:26 PM