ops-realtimestt
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/diagnose.pyemployssubprocess.runto execute shell commands such asdocker inspect,docker exec, andcurl. These are used to query container metadata, run GPU diagnostics inside containers, and perform transcription tests against ASR endpoints. - [EXTERNAL_DOWNLOADS]: The
health,doctor, andtranscribe-smokecommands utilizeurllib.requestandcurlto interact with external or local network endpoints. These network probes are used to verify the availability and response schemas of Whisper-compatible and Embry RealtimeSTT services. - [PROMPT_INJECTION]: The skill implements an
assesscommand that statically analyzes local source code to detect indirect prompt injection risks, specifically warning when ASR transcripts are used as an authoritative source for user or speaker identification. - [DATA_EXFILTRATION]: The skill accesses local file system paths through the
assess(file read for analysis) andtranscribe-smoke(audio file read) commands. It also collects environment variables from Docker containers, though it applies a redaction filter to prevent the exposure of sensitive keys such as tokens, secrets, or passwords.
Audit Metadata