audio-transcribe

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install openai-whisper and ffmpeg using package managers such as brew, pip, or apt-get. These are official packages from a well-known organization and standard system utilities.
  • [COMMAND_EXECUTION]: The skill uses os.shell.run to execute the whisper command-line tool for audio processing. It also utilizes shell commands for environment setup and health checks.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external audio files that could potentially contain spoken instructions designed to influence the agent (e.g., "ignore previous instructions"). The skill includes a mitigating instruction for the agent to answer strictly based on the transcript content and follow specific rules for data handling, though the risk is inherent to transcribing untrusted media.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:53 PM
Security Audit — agent-trust-hub — audio-transcribe