deepgram-js-conversational-stt
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill mentions installing a central product skill repository using
npx skills add deepgram/skills. This command targets the official resource of the vendor and is used for extending functionality with related documentation and recipes. - [INDIRECT_PROMPT_INJECTION]: The skill processes live audio streams for transcription, which represents a potential ingestion point for untrusted data. If an agent automatically follows instructions contained within the resulting transcription, this could lead to indirect prompt injection.
- Ingestion points:
deepgramConnection.sendMedia(chunk)inSKILL.md(via audio stream). - Boundary markers: None explicitly mentioned for the transcription output stream.
- Capability inventory: The skill enables network communication with Deepgram's API endpoints.
- Sanitization: No explicit sanitization or filtering is described for the generated transcriptions.
Audit Metadata