voice-lab

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The audio generation logic in voice_lab.py is vulnerable to Python code injection. The script assembles code using f-string interpolation of the text variable (sourced from user input) and executes it via subprocess.run([sys.executable, "-c", ...]). A maliciously crafted input string containing quotes and semicolons can execute arbitrary Python code.
  • [EXTERNAL_DOWNLOADS]: run.sh downloads and pipes the uv installer script from astral.sh directly to the shell. While originating from a well-known service provider, this pattern bypasses static analysis and poses a supply-chain risk if the remote source is compromised.
  • [COMMAND_EXECUTION]: The skill makes extensive use of high-privilege system commands to manage the host audio environment and external services. This includes using docker exec in sweep.py to run inference, and PipeWire utilities (pw-record, pw-play, wpctl, pw-link) across several files to manipulate audio routing and recording.
  • [DATA_EXFILTRATION]: lesson.py contains a path traversal vulnerability in its package creation logic. The source and scene parameters are used to construct the lesson_dir path without sanitization for parent directory characters (../), which could allow the skill to write files outside the intended media storage root.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting and rendering metadata (such as titles and descriptions) from YouTube and Jellyfin.
  • Ingestion points: content_provider.py (Jellyfin API), voice_lab.py (YouTube downloader).
  • Boundary markers: None present.
  • Capability inventory: High-risk capabilities including subprocess.run and docker exec are present in the same skill.
  • Sanitization: No sanitization logic was detected for external metadata fields.
Recommendations
  • HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — voice-lab