skills/deepgram/skills/cli/Gen Agent Trust Hub

cli

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the CLI installer and specialized skill files from official Deepgram sources, including deepgram.com and the vendor's GitHub organization.\n- [REMOTE_CODE_EXECUTION]: Includes instructions for installing the CLI using shell-piped commands (curl | sh and iwr | iex) directly from the official deepgram.com domain.\n- [COMMAND_EXECUTION]: Instructs the agent on how to execute the dg command-line utility for transcription, media synthesis, and account management.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external inputs such as audio files, URLs, and text documents for transcription and analysis tasks.\n
  • Ingestion points: The dg listen and dg read commands accept file paths and URLs as input (SKILL.md).\n
  • Boundary markers: The instructions do not define specific delimiters for untrusted content.\n
  • Capability inventory: The CLI tool performs network requests to Deepgram APIs and reads/writes local files.\n
  • Sanitization: No explicit sanitization or validation of external content is described in the prompt construction.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 04:17 AM
Security Audit — agent-trust-hub — cli