voice-ai-development
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides templates and patterns for building voice agents that process untrusted audio and text data from external users, which is a known attack surface for indirect prompt injection.
- Ingestion points: Data enters the agent's context through the
vapi_webhookFlask endpoint and thetranscribe_streamfunction (SKILL.md). - Boundary markers: The provided code snippets do not include prompt delimiters or instructions to ignore embedded commands within the processed transcripts (SKILL.md).
- Capability inventory: The skill demonstrates capabilities for network communication with AI provider APIs (OpenAI, Deepgram, ElevenLabs, Vapi) and includes patterns for tool/function calling (SKILL.md).
- Sanitization: The implementation patterns do not demonstrate sanitization or validation of the generated transcripts before they are passed to the language model (SKILL.md).
Audit Metadata