elevenlabs
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes text content from external scripts or user prompts to generate audio content, which presents a surface for instructions embedded in data.
- Ingestion points: Text content in SKILL.md and scripts like
VOICEOVER-SCRIPT.mdprocessed by the/generate-voiceoverworkflow. - Boundary markers: No explicit delimiters or boundary instructions are provided for the text sent to the audio synthesis engine.
- Capability inventory: The skill has capabilities for file system writing (
save,open), network communication (ElevenLabs API), and local command execution. - Sanitization: No sanitization or input validation for the text data is described in the provided instructions.
- [COMMAND_EXECUTION]: The skill requires the execution of shell commands for media processing and automation.
- Evidence: Usage of
ffmpegfor converting audio files anduv run tools/voiceover.pyfor generating scene-based audio assets.
Audit Metadata