tts-horus
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
taxonomy/taxonomy.pyusessubprocess.runto perform unversioned runtime package installation (pip install typer). - [COMMAND_EXECUTION]: The
taxonomy/taxonomy.pyscript searches for an external script namedbatch.pyin various system paths (including~/.claude/and~/.pi/home directories) and executes it usingsubprocess.runif found. - [PROMPT_INJECTION]: The
taxonomy/taxonomy.pyscript contains an indirect prompt injection surface. It takes untrusted input from files or command-line arguments and interpolates it directly into an LLM prompt template (PROMPT) without sanitization, escaping, or effective boundary markers. - Ingestion points: The
mainfunction intaxonomy/taxonomy.pyaccepts text via--textor file content via--file. - Boundary markers: No delimiters or instructions to ignore embedded commands are present in the prompt string.
- Capability inventory: The script has the ability to execute system commands via
subprocess.run. - Sanitization: Input is limited to the first 2000 characters, but no content validation or sanitization is performed.
- [EXTERNAL_DOWNLOADS]: The
SKILL.mddocumentation includes instructions to download model weights (dvae.pth) from HuggingFace (huggingface.co). This is a well-known service and the reference is documented for legitimate model acquisition.
Audit Metadata