text-to-speech
Pass
Audited by Gen Agent Trust Hub on Apr 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows security best practices by using the HEYGEN_API_KEY environment variable for authentication rather than hardcoding secrets.
- [SAFE]: All network communication is directed to official HeyGen domains (api.heygen.com, resource.heygen.ai, resource2.heygen.ai).
- [SAFE]: The code samples provided (TypeScript, Python, and curl) perform standard API operations for listing voices and generating audio without any hidden or obfuscated logic.
- [SAFE]: The skill uses a restricted set of tools defined in the YAML frontmatter (mcp__heygen__*), adhering to the principle of least privilege.
Audit Metadata