converse

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes sanity check scripts that download audio from YouTube. As YouTube is a well-known service and the download is for a specific, documented test track, this is considered a safe operational reference.
  • [COMMAND_EXECUTION]: The skill frequently uses the subprocess and asyncio.create_subprocess_exec modules to interface with system audio utilities such as PipeWire (pw-record, pw-play), ffmpeg, and TTS engines (espeak-ng, qwen3-tts). These operations are essential for its primary voice processing functions and use safe argument handling.
  • [SAFE]: The skill follows secure coding practices by using yaml.safe_load for scenario parsing and employing string escaping when constructing command-line calls for fallback TTS services. No malicious patterns such as obfuscation or credential exfiltration were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — converse