pp-fish-audio

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the fish-audio-pp-cli tool from the mvanhorn repository using npx and go install commands during setup.
  • [COMMAND_EXECUTION]: The skill executes the fish-audio-pp-cli binary to perform audio processing, manage local SQLite logs, and interact with the Fish Audio API.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input through its audio generation and transcription functions, which represents a potential injection surface.
  • Ingestion points: Processes user-provided text for speech generation in tts render and ingests audio data for transcription in the asr command. It also processes natural language queries for the recall and teach learning loop.
  • Boundary markers: None identified in the provided skill instructions.
  • Capability inventory: The skill can make network requests to the Fish Audio API, perform POST requests to external webhooks via the --deliver flag, and write data to local SQLite files.
  • Sanitization: No explicit sanitization or validation logic for external content is defined in the skill documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 02:30 PM
Security Audit — agent-trust-hub — pp-fish-audio