elevenlabs-tts

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill points to an external installation document located at https://raw.githubusercontent.com/inference-sh/skills/refs/heads/main/cli-install.md. This resource originates from an external repository that is not included in the trusted provider lists.
  • [REMOTE_CODE_EXECUTION]: The skill recommends adding further capabilities using npx skills add inference-sh/skills@... commands. These commands download and install external code packages into the agent's operating environment from a non-standard source.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection attacks:
  • Ingestion points: User-controlled data enters the agent context through the text parameter in the belt app run JSON payloads described in the examples.
  • Boundary markers: Absent. The instructions do not specify delimiters or provide guidance to the agent to isolate the text input from its instruction set.
  • Capability inventory: The skill possesses the capability to execute the belt CLI tool via a scoped Bash(belt *) permission.
  • Sanitization: Absent. There is no evidence of input validation, escaping, or filtering before the user-supplied text is passed to the shell command.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:20 PM
Security Audit — agent-trust-hub — elevenlabs-tts