text-intelligence
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation for interacting with the Deepgram Read API. All instructions and URLs are consistent with the vendor's primary purpose of providing text intelligence services.\n- [EXTERNAL_DOWNLOADS]: The skill references official Deepgram domains for API requests (
api.deepgram.com) and technical documentation (developers.deepgram.com). These are legitimate vendor resources used for the skill's intended functionality.\n- [CREDENTIALS_SAFE]: The provided code snippets demonstrate the correct use of an environment variable ($DEEPGRAM_API_KEY) for authentication rather than providing hardcoded secrets.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and process untrusted text data (e.g., support tickets, chat logs, or documents) via thetextorurlparameters.\n - Ingestion points: Data enters the context through the JSON payload (
textfield) or remote document fetching (urlfield) described inSKILL.md.\n - Boundary markers: None specified for the text input.\n
- Capability inventory: The skill executes a REST POST request to an external API (
api.deepgram.com) usingcurl.\n - Sanitization: No explicit sanitization of input text is mentioned.
Audit Metadata