deepgram-js-text-to-speech
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external text for audio synthesis. This constitutes an ingestion point for untrusted data (SKILL.md). While the provided examples do not include explicit boundary markers or sanitization logic, the skill's capability inventory is restricted to audio synthesis via the Deepgram API. It does not perform sensitive file writes, arbitrary command execution, or network exfiltration of local data, which mitigates the risk associated with processing untrusted inputs.
- [CREDENTIALS_UNSAFE]: The skill demonstrates secure handling of authentication credentials by retrieving the API key from environment variables (
process.env.DEEPGRAM_API_KEY) rather than hardcoding sensitive tokens, adhering to standard security practices. - [EXTERNAL_DOWNLOADS]: The skill references official Deepgram developer resources (developers.deepgram.com) and suggests adding related vendor skills via
npx. These references are part of the established vendor ecosystem and represent expected documentation behavior.
Audit Metadata