text-to-speech

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest untrusted text data and process it for audio synthesis. This creates a surface for indirect prompt injection where instructions could be embedded in the data to influence agent behavior or synthesis output.
  • Ingestion points: Data enters via the synthesize method in SecureTTSEngine (SKILL.md) and the filter method in TTSContentFilter (references/security-examples.md).
  • Boundary markers: The implementation lacks explicit boundary delimiters to isolate input text, though it mandates preprocessing steps and content filtering.
  • Capability inventory: The skill uses sf.write for file system writes, os.chmod for permission management, shutil.rmtree for deletion, and sounddevice for hardware audio output.
  • Sanitization: The skill implements several defensive measures, including regex filtering for sensitive patterns (passwords, API keys, tokens), length constraints (max 5000 characters), and character validation to strip shell-sensitive characters like ;, |, and &.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:54 PM
Security Audit — agent-trust-hub — text-to-speech