voice-segment-selector
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runto callffmpegandffprobefor audio manipulation tasks, such as normalization, duration checking, and clipping. The arguments are passed as lists rather than shell strings, which effectively prevents command injection vulnerabilities. - [COMMAND_EXECUTION]: In
scripts/lib/orpheus_handoff.py, the skill executeszsh -lic "print -r -- ${HF_TOKEN}"to retrieve the Hugging Face API token from the user's shell environment. This is a functional requirement for publishing datasets to Hugging Face repositories and uses a specific, non-malleable command. - [EXTERNAL_DOWNLOADS]: The skill downloads pre-trained machine learning models from Hugging Face, including
norwood-maleVSfemalefor gender classification and an AudioSet AST model for emotion classification. These models are standard components for the skill's stated purpose. - [SAFE]: The skill implements a local review server using FastAPI. The endpoint for serving audio clips (
/clips/{clip_path:path}) includes robust path traversal protection by using.resolve()and verifying that the resulting path remains within the designated job directory. - [SAFE]: The
eval()call flagged by static analysis inscripts/lib/orpheus_audio_classifier.pyis a false positive; it refers to the PyTorchmodel.eval()method, which simply sets a neural network to evaluation mode and has no security implications.
Audit Metadata