byted-text-to-speech
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill's behavior is consistent with its stated purpose of providing text-to-speech services using the Volcengine Doubao Speech API.
- [CREDENTIALS_SAFE]: The skill demonstrates safe credential handling. It prioritizes the
MODEL_SPEECH_API_KEYfrom the environment and provides a setup utility inscripts/api_key.pyto automatically fetch or create keys using a primary Ark API key. When persisting credentials to a.envfile, it correctly restricts file permissions to0o600(read/write by owner only). - [EXTERNAL_DOWNLOADS]: The skill relies on the
httpxlibrary for API requests as specified inrequirements.txt. It does not download or execute any third-party scripts or unverified remote code. - [DATA_EXFILTRATION]: Network requests are exclusively sent to official ByteDance/Volcengine domains (
openspeech.bytedance.comand related API bases). No sensitive system information or local files are transmitted to external endpoints. - [COMMAND_EXECUTION]: The skill uses Python's standard libraries and the
httpxclient to interact with web APIs. It does not invoke shell commands or execute arbitrary system processes based on user input.
Audit Metadata