elevenlabs-sound-effects

Pass

Audited by Gen Agent Trust Hub on Apr 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill primarily serves as documentation for using the infsh CLI to access sound generation services. All commands and URLs are associated with the vendor's official domains and repositories.
  • [COMMAND_EXECUTION]: The skill uses the infsh tool to execute applications on the vendor's platform. These operations are within the scope defined in the allowed-tools configuration.
  • [EXTERNAL_DOWNLOADS]: The documentation links to installation instructions hosted on the vendor's GitHub repository (inference-sh/skills). This is a legitimate reference for setting up the required CLI environment.
  • [PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection as it processes user-supplied text descriptions to generate audio.
  • Ingestion points: The text parameter in the infsh app run command within SKILL.md.
  • Boundary markers: None present in the provided examples.
  • Capability inventory: Subprocess execution via the infsh CLI tool.
  • Sanitization: No explicit sanitization or input validation is described in the markdown documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 23, 2026, 12:06 PM
Security Audit — agent-trust-hub — elevenlabs-sound-effects