elevenlabs-stt

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the belt CLI tool and installation scripts hosted on GitHub (github.com/inference-sh) and the inference.sh platform. These are standard dependencies for the service's functionality.
  • [COMMAND_EXECUTION]: The skill is configured to use the belt command-line interface via Bash for processing audio transcription requests. The scope is restricted to the belt tool as defined in the allowed-tools frontmatter.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface (Category 8) as it processes transcription output from external audio files. However, this is inherent to speech-to-text services, and no high-risk capabilities are directly exposed to the untrusted output without agent mediation.
  • [DATA_EXFILTRATION]: Audio data URLs are transmitted to the inference.sh API for processing. This is the intended primary purpose of the skill and does not involve sensitive local file access or unauthorized data transfer.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 10:40 PM
Security Audit — agent-trust-hub — elevenlabs-stt