deepgram-python-text-to-speech
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external text data (such as tokens generated by an LLM) and convert it into audio, creating an attack surface for indirect prompt injection.
- Ingestion points: Data enters the context via the
textparameter in theclient.speak.v1.audio.generatemethod (REST) and theSpeakV1Textobject in theconn.send_textmethod (WebSocket). - Boundary markers: No specific delimiters or instructions to ignore embedded commands are demonstrated in the provided code snippets.
- Capability inventory: The skill possesses the capability to perform network requests to the Deepgram API and write binary audio data to the local file system (e.g.,
output.raw). - Sanitization: The documentation does not demonstrate explicit input sanitization or validation of the text string before it is sent to the synthesis engine.
- [COMMAND_EXECUTION]: The skill provides a command-line instruction to expand the agent's capabilities using the
npxpackage runner. - Evidence:
npx skills add deepgram/skillsin the 'Central product skills' section. - Analysis: The command is used to install additional skills from the official vendor's repository (
deepgram/skills), which is an expected action within the context of using the vendor's SDK tools.
Audit Metadata