voice-segment-selector

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to call ffmpeg and ffprobe for audio manipulation tasks, such as normalization, duration checking, and clipping. The arguments are passed as lists rather than shell strings, which effectively prevents command injection vulnerabilities.
  • [COMMAND_EXECUTION]: In scripts/lib/orpheus_handoff.py, the skill executes zsh -lic "print -r -- ${HF_TOKEN}" to retrieve the Hugging Face API token from the user's shell environment. This is a functional requirement for publishing datasets to Hugging Face repositories and uses a specific, non-malleable command.
  • [EXTERNAL_DOWNLOADS]: The skill downloads pre-trained machine learning models from Hugging Face, including norwood-maleVSfemale for gender classification and an AudioSet AST model for emotion classification. These models are standard components for the skill's stated purpose.
  • [SAFE]: The skill implements a local review server using FastAPI. The endpoint for serving audio clips (/clips/{clip_path:path}) includes robust path traversal protection by using .resolve() and verifying that the resulting path remains within the designated job directory.
  • [SAFE]: The eval() call flagged by static analysis in scripts/lib/orpheus_audio_classifier.py is a false positive; it refers to the PyTorch model.eval() method, which simply sets a neural network to evaluation mode and has no security implications.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — voice-segment-selector