elevenlabs-stt
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references installation instructions from a GitHub repository and uses npx to add related skills from the inference-sh and belt-sh organizations. These downloads are associated with the primary service provider for this tool.
- [INDIRECT_PROMPT_INJECTION]: The skill processes audio data and text from external URLs, which constitutes an ingestion point for untrusted content.
- Ingestion points: audio and text input fields for transcription and forced alignment (SKILL.md).
- Boundary markers: Absent.
- Capability inventory: Restricted to belt command execution via Bash.
- Sanitization: Absent.
Audit Metadata