byted-text-to-speech

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill's behavior is consistent with its stated purpose of providing text-to-speech services using the Volcengine Doubao Speech API.
  • [CREDENTIALS_SAFE]: The skill demonstrates safe credential handling. It prioritizes the MODEL_SPEECH_API_KEY from the environment and provides a setup utility in scripts/api_key.py to automatically fetch or create keys using a primary Ark API key. When persisting credentials to a .env file, it correctly restricts file permissions to 0o600 (read/write by owner only).
  • [EXTERNAL_DOWNLOADS]: The skill relies on the httpx library for API requests as specified in requirements.txt. It does not download or execute any third-party scripts or unverified remote code.
  • [DATA_EXFILTRATION]: Network requests are exclusively sent to official ByteDance/Volcengine domains (openspeech.bytedance.com and related API bases). No sensitive system information or local files are transmitted to external endpoints.
  • [COMMAND_EXECUTION]: The skill uses Python's standard libraries and the httpx client to interact with web APIs. It does not invoke shell commands or execute arbitrary system processes based on user input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 01:42 AM
Security Audit — agent-trust-hub — byted-text-to-speech