elevenlabs-stt

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the belt CLI tool via npx skills add belt-sh/cli and points to configuration files on GitHub hosted by inference-sh.
  • [COMMAND_EXECUTION]: The skill uses the belt command-line utility to interact with speech-to-text models, utilizing the Bash(belt *) tool capability.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through the ingestion of external data.
  • Ingestion points: Audio file URLs and alignment text strings provided in the SKILL.md examples.
  • Boundary markers: None identified in the provided instructions or command examples.
  • Capability inventory: Shell command execution via the belt CLI tool.
  • Sanitization: No explicit sanitization or validation of the input data or transcription output is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 06:32 PM
Security Audit — agent-trust-hub — elevenlabs-stt