deepgram-js-text-to-speech

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external text for audio synthesis. This constitutes an ingestion point for untrusted data (SKILL.md). While the provided examples do not include explicit boundary markers or sanitization logic, the skill's capability inventory is restricted to audio synthesis via the Deepgram API. It does not perform sensitive file writes, arbitrary command execution, or network exfiltration of local data, which mitigates the risk associated with processing untrusted inputs.
  • [CREDENTIALS_UNSAFE]: The skill demonstrates secure handling of authentication credentials by retrieving the API key from environment variables (process.env.DEEPGRAM_API_KEY) rather than hardcoding sensitive tokens, adhering to standard security practices.
  • [EXTERNAL_DOWNLOADS]: The skill references official Deepgram developer resources (developers.deepgram.com) and suggests adding related vendor skills via npx. These references are part of the established vendor ecosystem and represent expected documentation behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:53 PM
Security Audit — agent-trust-hub — deepgram-js-text-to-speech