voice-assist

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the SN-Execute-Background-Script tool for administrative tasks, including the configuration of system properties for telephony providers and the generation of usage analytics. The scripts provided are specific to voice configuration and do not attempt to execute unauthorized commands outside the scope of ServiceNow administration.
  • [CREDENTIALS_UNSAFE]: In Step 6, the skill provides a template for configuring Twilio telephony integration. It correctly uses placeholders like [twilio_account_sid] for sensitive credentials rather than hardcoding actual values, which is a safe practice for shared instructions.
  • [PROMPT_INJECTION]: The skill involves the creation of voice-enabled conversation flows that process untrusted input from callers. While this creates a surface for indirect prompt injection (where malicious speech could be stored and later processed), the skill includes 'Best Practices' such as 'Confirmation Steps' for critical inputs and identity verification, which serve as mitigations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 02:23 PM
Security Audit — agent-trust-hub — voice-assist