text-intelligence

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation for interacting with the Deepgram Read API. All instructions and URLs are consistent with the vendor's primary purpose of providing text intelligence services.\n- [EXTERNAL_DOWNLOADS]: The skill references official Deepgram domains for API requests (api.deepgram.com) and technical documentation (developers.deepgram.com). These are legitimate vendor resources used for the skill's intended functionality.\n- [CREDENTIALS_SAFE]: The provided code snippets demonstrate the correct use of an environment variable ($DEEPGRAM_API_KEY) for authentication rather than providing hardcoded secrets.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and process untrusted text data (e.g., support tickets, chat logs, or documents) via the text or url parameters.\n
  • Ingestion points: Data enters the context through the JSON payload (text field) or remote document fetching (url field) described in SKILL.md.\n
  • Boundary markers: None specified for the text input.\n
  • Capability inventory: The skill executes a REST POST request to an external API (api.deepgram.com) using curl.\n
  • Sanitization: No explicit sanitization of input text is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 04:17 AM
Security Audit — agent-trust-hub — text-intelligence