skills/daxaur/openpaw/c-voice/Gen Agent Trust Hub

c-voice

Pass

Audited by Gen Agent Trust Hub on Mar 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines usage patterns for the macOS built-in 'say' command and the 'sag' CLI tool for ElevenLabs integration for audio synthesis and transcription.
  • [PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by processing transcribed text from untrusted audio sources. 1. Ingestion points: Transcription results from the 'sag' tool derived from external files or live recordings. 2. Boundary markers: No delimiters or isolation instructions are defined for the transcribed content. 3. Capability inventory: Local command execution for audio processing. 4. Sanitization: No evidence of text sanitization or validation for the transcription output before processing by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 9, 2026, 08:44 AM
Security Audit — agent-trust-hub — c-voice