skills/joeseesun/qiaomu-cut-skill/asr/Gen Agent Trust Hub

asr

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @marswave/coli NPM package and suggests system tools like ffmpeg. Machine learning models are also downloaded to the user's home directory during use.
  • [COMMAND_EXECUTION]: Shell commands are used for environment verification, configuration management, and execution of the transcription tool. The skill also performs file system write operations to save transcriptions.
  • [INDIRECT_PROMPT_INJECTION]: Untrusted audio data is transcribed and then processed by the AI for refinement, creating a surface where instructions within the audio could influence the agent. * Ingestion points: User-provided audio files (Step 1). * Boundary markers: None present during the AI polishing step. * Capability inventory: Shell command execution and file system access. * Sanitization: No sanitization of transcribed text is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 08:21 PM
Security Audit — agent-trust-hub — asr