audiobook-creator

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the Kokoro TTS model and voices from GitHub during the initial execution. This is a standard procedure for local machine learning applications to acquire model weights.
  • [COMMAND_EXECUTION]: Executes the ffmpeg system utility via subprocess.run to encode audio files and embed chapter metadata. The command is constructed using a list of arguments, which is a safe practice that prevents shell injection attacks.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests text from external documents (PDF, DOCX, Markdown) provided by the user. These files could potentially contain malicious instructions aimed at the agent. However, the skill provides specific guidance to the agent on how to sanitize the extracted text and requires a strict JSON schema for the final audio generation step, mitigating the risk of unintended actions.
  • [CREDENTIALS_SAFE]: No hardcoded secrets, API keys, or sensitive credential access patterns were detected. The skill operates locally and requires the user to specify a local output directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 02:54 AM
Security Audit — agent-trust-hub — audiobook-creator