transcribe-and-analyze

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from media transcripts and passes it directly into an LLM prompt for analysis without sufficient isolation.
  • Ingestion points: In scripts/analyze_transcript.py, the read_transcript function reads the contents of a transcript file which was generated from an external URL.
  • Boundary markers: The analyze_transcript function interpolates the transcript text directly into the user_message using simple string formatting (e.g., user_message = f"Please analyze this transcript:\n\n{transcript_text}") without using delimiters or instructions to ignore embedded commands.
  • Capability inventory: The script has the ability to write files to the local filesystem and send data to external AI providers (OpenAI API or local Ollama).
  • Sanitization: No sanitization or filtering is performed on the transcript text before it is sent to the LLM.
  • [COMMAND_EXECUTION]: The script scripts/transcribe.py uses subprocess.run() to execute external CLI tools.
  • It invokes yt-dlp for media downloading and whisperkit-cli for local transcription.
  • While the commands use list-based arguments which mitigate shell injection, the skill relies on the proper installation and security of these external binaries.
  • [EXTERNAL_DOWNLOADS]: The skill depends on external software that must be downloaded and installed by the user.
  • It requires yt-dlp (via pip or brew) and whisperkit-cli (from the argmaxinc/WhisperKit GitHub repository) to function.
  • scripts/transcribe.py downloads media files from user-provided URLs using yt-dlp to a temporary directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:04 AM
Security Audit — agent-trust-hub — transcribe-and-analyze