tts-horus

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script taxonomy/taxonomy.py uses subprocess.run to perform unversioned runtime package installation (pip install typer).
  • [COMMAND_EXECUTION]: The taxonomy/taxonomy.py script searches for an external script named batch.py in various system paths (including ~/.claude/ and ~/.pi/ home directories) and executes it using subprocess.run if found.
  • [PROMPT_INJECTION]: The taxonomy/taxonomy.py script contains an indirect prompt injection surface. It takes untrusted input from files or command-line arguments and interpolates it directly into an LLM prompt template (PROMPT) without sanitization, escaping, or effective boundary markers.
  • Ingestion points: The main function in taxonomy/taxonomy.py accepts text via --text or file content via --file.
  • Boundary markers: No delimiters or instructions to ignore embedded commands are present in the prompt string.
  • Capability inventory: The script has the ability to execute system commands via subprocess.run.
  • Sanitization: Input is limited to the first 2000 characters, but no content validation or sanitization is performed.
  • [EXTERNAL_DOWNLOADS]: The SKILL.md documentation includes instructions to download model weights (dvae.pth) from HuggingFace (huggingface.co). This is a well-known service and the reference is documented for legitimate model acquisition.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — tts-horus