liveavatar-integrate

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and recommends the official HeyGen Web SDK (@heygen/liveavatar-web-sdk) and points to its public GitHub repository (heygen-com/liveavatar-web-sdk). It also mentions well-known services such as LiveKit, ElevenLabs, and Agora as part of the integration ecosystem.
  • [CREDENTIALS_UNSAFE]: The skill scans for API keys in configuration files like .env to detect existing setup. It adheres to security best practices by explicitly warning against exposing secret keys in client-side code and providing guidance on secure backend storage.
  • [INDIRECT_PROMPT_INJECTION]: The skill scans local project files (e.g., package.json, requirements.txt, .env) to identify dependencies and configurations. While this involves processing untrusted data, it is used solely for determining integration recommendations.
  • Ingestion points: package.json, .env, requirements.txt, and source code imports.
  • Boundary markers: Not explicitly defined in the discovery instructions.
  • Capability inventory: Primarily instructional; the skill generates code snippets but does not contain instructions for the agent to execute shell commands or network operations autonomously.
  • Sanitization: None specified for the discovery phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:00 AM
Security Audit — agent-trust-hub — liveavatar-integrate