elevenlabs-stt
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the installation of the
beltCLI tool vianpx skills add belt-sh/cliand points to configuration files on GitHub hosted byinference-sh. - [COMMAND_EXECUTION]: The skill uses the
beltcommand-line utility to interact with speech-to-text models, utilizing theBash(belt *)tool capability. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through the ingestion of external data.
- Ingestion points: Audio file URLs and alignment text strings provided in the
SKILL.mdexamples. - Boundary markers: None identified in the provided instructions or command examples.
- Capability inventory: Shell command execution via the
beltCLI tool. - Sanitization: No explicit sanitization or validation of the input data or transcription output is described.
Audit Metadata