text-to-speech
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest untrusted text data and process it for audio synthesis. This creates a surface for indirect prompt injection where instructions could be embedded in the data to influence agent behavior or synthesis output.
- Ingestion points: Data enters via the
synthesizemethod inSecureTTSEngine(SKILL.md) and thefiltermethod inTTSContentFilter(references/security-examples.md). - Boundary markers: The implementation lacks explicit boundary delimiters to isolate input text, though it mandates preprocessing steps and content filtering.
- Capability inventory: The skill uses
sf.writefor file system writes,os.chmodfor permission management,shutil.rmtreefor deletion, andsounddevicefor hardware audio output. - Sanitization: The skill implements several defensive measures, including regex filtering for sensitive patterns (passwords, API keys, tokens), length constraints (max 5000 characters), and character validation to strip shell-sensitive characters like
;,|, and&.
Audit Metadata