narova-openai

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill operates by executing a local Python worker script (tool/worker.py). A setup script (tool/setup.sh) is provided to verify that the environment has the necessary Python standard library modules available before registration.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill utilizes the OPENAI_API_KEY environment variable for authentication. This sensitive information is transmitted only to OpenAI's official API endpoint (https://api.openai.com) via a standard Authorization header to perform speech synthesis, which is the skill's documented primary purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests text data from the Narova agent to generate audio.
  • Ingestion points: Untrusted text enters the agent context through sys.stdin in tool/worker.py as part of the JSONL protocol.
  • Boundary markers: The skill does not implement specific boundary markers or delimiters for the ingested text, relying on the structural separation provided by the JSONL protocol.
  • Capability inventory: Across its scripts, the skill has the capability to write audio files to the local filesystem (tool/worker.py) and perform network operations to OpenAI's servers.
  • Sanitization: The skill enforces strict length limits on input text and instructions, and includes path validation logic to ensure output audio files are written to valid, absolute paths without following symbolic links.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 02:06 AM
Security Audit — agent-trust-hub — narova-openai