deepgram-python-voice-agent

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of a voice agent that ingests untrusted user audio and text messages as its primary function. While this presents an inherent surface for indirect prompt injection, no malicious prompts or bypass techniques were found in the provided instructions.
  • Ingestion points: User audio chunks via agent.send_media and text via AgentV1InjectUserMessage in SKILL.md.
  • Boundary markers: Absent in the quick start examples; instructions for protecting the system prompt from user input are not explicitly provided.
  • Capability inventory: The skill is scoped to Deepgram API interactions (STT, TTS, and LLM orchestration). No local command execution, file system modifications, or arbitrary network access capabilities are present.
  • Sanitization: Not explicitly implemented in the example code snippets.
  • [EXTERNAL_DOWNLOADS]: The documentation suggests installing additional vendor-specific resources via npx skills add deepgram/skills. This operation targets the official repository of the skill's author.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 11:24 AM
Security Audit — agent-trust-hub — deepgram-python-voice-agent