openrouter-transcribe

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted audio files and returns the resulting transcript directly to the agent's context, which could influence subsequent agent behavior if the audio contains malicious instructions.
  • Ingestion points: The input audio file path processed by scripts/transcribe.sh at line 31.
  • Boundary markers: Absent. The raw transcript from the API is returned directly to stdout or a file without delimiters or 'ignore' instructions.
  • Capability inventory: The script executes ffmpeg for conversion, curl for network access, and can write to the filesystem using the --out argument.
  • Sanitization: Absent. No filtering or validation is performed on the transcription content before it is output to the agent.
  • [COMMAND_EXECUTION]: The script executes multiple system commands using input provided by the agent.
  • The scripts/transcribe.sh script uses ffmpeg, base64, jq, and curl to process the audio data.
  • The --out parameter (line 120) allows the agent to specify an arbitrary file path for writing the output, which could be misused to overwrite sensitive local files if the agent is misled by the content of a transcription.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — openrouter-transcribe