transcript-workflows

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the jake-tools CLI and ffmpeg for its core transcription and audio processing tasks. It also employs environmental management commands like unset PYTHONPATH to ensure a clean execution context. All commands are limited to the intended workflow of processing media and transcripts.- [DATA_EXPOSURE]: The skill accesses specific local file paths including ~/Documents/Vault (for Obsidian notes) and ~/.claude/projects/ (for reading Claude session logs). These operations are restricted to relevant note-taking and debugging activities required for the transcript workflow.- [SAFE]: The instructions implement several security-positive constraints, such as prohibiting the agent from improvising workarounds for missing features and explicitly warning against requesting sensitive credentials like Graph API client secrets. It also frames transcript content as evidence to be processed rather than instructions to be followed, reducing the risk of indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 03:04 PM
Security Audit — agent-trust-hub — transcript-workflows