byteplus-seed-speech-tts

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents the official integration process for the BytePlus Seed Speech text-to-speech service. It emphasizes secure practices, such as using environment variables for sensitive API keys (${BYTEPLUS_API_KEY}) rather than hardcoding credentials.
  • [DATA_EXPOSURE]: The instructions explicitly warn against logging sensitive information, including API keys, tokens, and customer-provided source text, which protects against accidental data leakage during debugging or production logging.
  • [PROMPT_INJECTION]: While the skill processes user-supplied text for speech synthesis (a potential ingestion surface for indirect prompt injection), it recommends proactive mitigations such as text normalization, validation of character counts, and sanitization of Markdown or emojis before sending data to the external API.
  • [EXTERNAL_DOWNLOADS]: All referenced URLs point to legitimate, well-known domains associated with the service provider (byteplus.com and bytepluses.com) for documentation, console access, and API endpoints. The skill maintains a clear distinction between international endpoints and mainland China endpoints to ensure compliance and data residency requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 03:05 PM
Security Audit — agent-trust-hub — byteplus-seed-speech-tts