voice-lab
Fail
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The audio generation logic in
voice_lab.pyis vulnerable to Python code injection. The script assembles code using f-string interpolation of thetextvariable (sourced from user input) and executes it viasubprocess.run([sys.executable, "-c", ...]). A maliciously crafted input string containing quotes and semicolons can execute arbitrary Python code. - [EXTERNAL_DOWNLOADS]:
run.shdownloads and pipes theuvinstaller script fromastral.shdirectly to the shell. While originating from a well-known service provider, this pattern bypasses static analysis and poses a supply-chain risk if the remote source is compromised. - [COMMAND_EXECUTION]: The skill makes extensive use of high-privilege system commands to manage the host audio environment and external services. This includes using
docker execinsweep.pyto run inference, and PipeWire utilities (pw-record,pw-play,wpctl,pw-link) across several files to manipulate audio routing and recording. - [DATA_EXFILTRATION]:
lesson.pycontains a path traversal vulnerability in its package creation logic. Thesourceandsceneparameters are used to construct thelesson_dirpath without sanitization for parent directory characters (../), which could allow the skill to write files outside the intended media storage root. - [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting and rendering metadata (such as titles and descriptions) from YouTube and Jellyfin.
- Ingestion points:
content_provider.py(Jellyfin API),voice_lab.py(YouTube downloader). - Boundary markers: None present.
- Capability inventory: High-risk capabilities including
subprocess.runanddocker execare present in the same skill. - Sanitization: No sanitization logic was detected for external metadata fields.
Recommendations
- HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata