train-voice

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script iterative.py constructs Python code as a string and executes it using subprocess.run with the -c flag. This string contains the phrase variable interpolated from the --eval-phrases command-line argument. This pattern is vulnerable to Python code injection if an attacker can influence the input provided to the training command.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data by transcribing audio from YouTube using OpenAI Whisper in train.py. The transcripts are stored in JSONL manifests and processed during training without explicit sanitization or boundary markers. This creates a surface where malicious instructions spoken in the source audio could potentially influence the agent when it reads the resulting files.
  • [COMMAND_EXECUTION]: Multiple files including train.py, design.py, iterative.py, and batch_train.py make frequent use of subprocess.run to execute shell commands. These calls are used for audio processing via ffmpeg, process management with pgrep, and orchestrating training phases with python and uv.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to download audio from YouTube (train.py) and ML models from Hugging Face (sft_12hz.py and iterative.py). While these are well-known services relevant to the skill's ML purpose, they represent external data dependencies.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — train-voice