asr
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@marswave/coliNPM package and suggests system tools likeffmpeg. Machine learning models are also downloaded to the user's home directory during use. - [COMMAND_EXECUTION]: Shell commands are used for environment verification, configuration management, and execution of the transcription tool. The skill also performs file system write operations to save transcriptions.
- [INDIRECT_PROMPT_INJECTION]: Untrusted audio data is transcribed and then processed by the AI for refinement, creating a surface where instructions within the audio could influence the agent. * Ingestion points: User-provided audio files (Step 1). * Boundary markers: None present during the AI polishing step. * Capability inventory: Shell command execution and file system access. * Sanitization: No sanitization of transcribed text is performed.
Audit Metadata