elevenlabs-tts
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The helper script reads
ELEVENLABS_API_KEYfrom the environment or local.envfiles and transmits it toapi.elevenlabs.io. This is the intended behavior for an API integration and targets a well-known service. - [INDIRECT_PROMPT_INJECTION]: The skill processes text from external files, standard input, or command-line arguments to generate speech audio.
- Ingestion points: The
generate_voice.pyscript accepts text input through the--textargument,--text-filepath, or viastdin. - Boundary markers: The skill does not implement specific delimiters or instructions to prevent the agent from interpreting instructions contained within the text files it processes.
- Capability inventory: The skill has the capability to perform network POST requests to the ElevenLabs API and write audio files to the local filesystem.
- Sanitization: The script uses a
slugifyfunction to sanitize profile and voice names before using them in output filenames, which helps prevent basic path traversal attempts.
Audit Metadata