web-audio-api
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements speech recognition functionality that converts voice input into text transcripts. This creates a vulnerability surface where malicious voice commands could be injected into the agent's context.\n
- Ingestion points: The
onresulthandler within theuseSpeechRecognitionhook inreferences/advanced-patterns.mdcaptures transcripts fromwindow.SpeechRecognition.\n - Boundary markers: The implementation does not show any delimiting or instructions to the model to ignore embedded commands within the captured text.\n
- Capability inventory: The skill utilizes standard Web Audio API nodes (Oscillators, Gain, Filters, Panners) and Browser APIs; no OS-level command execution or file system writing capabilities are defined in the scripts.\n
- Sanitization: No transcript sanitization, filtering, or validation is implemented in the provided speech processing patterns.\n- [DATA_EXFILTRATION]: The skill requests and processes sensitive audio data from the user's microphone using
navigator.mediaDevices.getUserMediainSKILL.md. The implementation follows safety best practices by requiring a user gesture before starting the audio context and providing explicit cleanup methods to stop the stream.\n- [EXTERNAL_DOWNLOADS]: ThecreateReverbfunction inreferences/advanced-patterns.mdusesfetch()to download audio impulse response files from an external URL. This is a common pattern for convolution reverb effects but involves fetching remote binary assets into the application context.\n- [DYNAMIC_EXECUTION]: The skill utilizesAudioWorkletandaddModuleto load and execute custom audio processors inSKILL.mdandreferences/advanced-patterns.md. While standard Web Audio API features, this involves loading and running scripts in a separate audio thread.
Audit Metadata