deepgram-js-speech-to-text

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents interfaces for processing external audio data which constitutes a potential injection surface.
  • Ingestion points: The methods transcribeUrl and transcribeFile in SKILL.md ingest external audio URLs and local file streams.
  • Boundary markers: No specific boundary markers or "ignore instructions" prompts are included in the code examples, as they are standard SDK implementations.
  • Capability inventory: The SDK performs network requests to the Deepgram API and can read local files via fs.createReadStream.
  • Sanitization: The examples demonstrate raw output logging; downstream applications should sanitize transcription results before further processing.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install related components using npx skills add deepgram/skills.
  • Evidence: The command in SKILL.md references the deepgram/skills repository.
  • Context: As this is the official repository of the skill's author (Deepgram), it is considered a legitimate vendor resource for cross-language product knowledge.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:02 PM
Security Audit — agent-trust-hub — deepgram-js-speech-to-text