ingest-voice-note

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted audio data, creating an indirect prompt injection surface.\n
  • Ingestion points: Audio files provided as $ARGUMENTS are transcribed via Whisper (SKILL.md).\n
  • Boundary markers: No delimiters or safety instructions are used when placing the transcript into the note body.\n
  • Capability inventory: Access to Bash, Read, and Write tools; executes ffmpeg, ffprobe, whisper-cli, and curl (SKILL.md).\n
  • Sanitization: Transcript content is cat'ed into the note without escaping or validation, though the file slug is sanitized.\n- [COMMAND_EXECUTION]: The workflow uses shell scripts to process the $ARGUMENTS input. While properly double-quoted, this pattern relies on the platform to validate that the input is a legitimate file path to prevent unexpected shell behavior or access to sensitive local files.\n- [EXTERNAL_DOWNLOADS]: The skill recommends installing whisper-cpp and openai-whisper via system package managers. It also optionally sends data to OpenAI's transcription API.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 01:51 PM
Security Audit — agent-trust-hub — ingest-voice-note