elevenlabs-tts
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill points to an external installation document located at
https://raw.githubusercontent.com/inference-sh/skills/refs/heads/main/cli-install.md. This resource originates from an external repository that is not included in the trusted provider lists. - [REMOTE_CODE_EXECUTION]: The skill recommends adding further capabilities using
npx skills add inference-sh/skills@...commands. These commands download and install external code packages into the agent's operating environment from a non-standard source. - [INDIRECT_PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection attacks:
- Ingestion points: User-controlled data enters the agent context through the
textparameter in thebelt app runJSON payloads described in the examples. - Boundary markers: Absent. The instructions do not specify delimiters or provide guidance to the agent to isolate the
textinput from its instruction set. - Capability inventory: The skill possesses the capability to execute the
beltCLI tool via a scopedBash(belt *)permission. - Sanitization: Absent. There is no evidence of input validation, escaping, or filtering before the user-supplied text is passed to the shell command.
Audit Metadata