ops-realtimestt

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/diagnose.py employs subprocess.run to execute shell commands such as docker inspect, docker exec, and curl. These are used to query container metadata, run GPU diagnostics inside containers, and perform transcription tests against ASR endpoints.
  • [EXTERNAL_DOWNLOADS]: The health, doctor, and transcribe-smoke commands utilize urllib.request and curl to interact with external or local network endpoints. These network probes are used to verify the availability and response schemas of Whisper-compatible and Embry RealtimeSTT services.
  • [PROMPT_INJECTION]: The skill implements an assess command that statically analyzes local source code to detect indirect prompt injection risks, specifically warning when ASR transcripts are used as an authoritative source for user or speaker identification.
  • [DATA_EXFILTRATION]: The skill accesses local file system paths through the assess (file read for analysis) and transcribe-smoke (audio file read) commands. It also collects environment variables from Docker containers, though it applies a redaction filter to prevent the exposure of sensitive keys such as tokens, secrets, or passwords.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — ops-realtimestt