openrouter-transcribe
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted audio files and returns the resulting transcript directly to the agent's context, which could influence subsequent agent behavior if the audio contains malicious instructions.
- Ingestion points: The input audio file path processed by
scripts/transcribe.shat line 31. - Boundary markers: Absent. The raw transcript from the API is returned directly to stdout or a file without delimiters or 'ignore' instructions.
- Capability inventory: The script executes
ffmpegfor conversion,curlfor network access, and can write to the filesystem using the--outargument. - Sanitization: Absent. No filtering or validation is performed on the transcription content before it is output to the agent.
- [COMMAND_EXECUTION]: The script executes multiple system commands using input provided by the agent.
- The
scripts/transcribe.shscript usesffmpeg,base64,jq, andcurlto process the audio data. - The
--outparameter (line 120) allows the agent to specify an arbitrary file path for writing the output, which could be misused to overwrite sensitive local files if the agent is misled by the content of a transcription.
Audit Metadata