transcribe-and-analyze
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from media transcripts and passes it directly into an LLM prompt for analysis without sufficient isolation.
- Ingestion points: In
scripts/analyze_transcript.py, theread_transcriptfunction reads the contents of a transcript file which was generated from an external URL. - Boundary markers: The
analyze_transcriptfunction interpolates the transcript text directly into theuser_messageusing simple string formatting (e.g.,user_message = f"Please analyze this transcript:\n\n{transcript_text}") without using delimiters or instructions to ignore embedded commands. - Capability inventory: The script has the ability to write files to the local filesystem and send data to external AI providers (OpenAI API or local Ollama).
- Sanitization: No sanitization or filtering is performed on the transcript text before it is sent to the LLM.
- [COMMAND_EXECUTION]: The script
scripts/transcribe.pyusessubprocess.run()to execute external CLI tools. - It invokes
yt-dlpfor media downloading andwhisperkit-clifor local transcription. - While the commands use list-based arguments which mitigate shell injection, the skill relies on the proper installation and security of these external binaries.
- [EXTERNAL_DOWNLOADS]: The skill depends on external software that must be downloaded and installed by the user.
- It requires
yt-dlp(via pip or brew) andwhisperkit-cli(from the argmaxinc/WhisperKit GitHub repository) to function. scripts/transcribe.pydownloads media files from user-provided URLs usingyt-dlpto a temporary directory.
Audit Metadata