skills/noizai/skills/chat-with-anyone/Gen Agent Trust Hub

chat-with-anyone

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run in scripts/extract_ref_segment.py to call ffmpeg. This is a legitimate and necessary use case for extracting audio segments from video files and does not involve untrusted user input in the command structure.
  • [EXTERNAL_DOWNLOADS]: The skill downloads media from YouTube and Bilibili using the well-known yt-dlp tool. This is the core functionality of the skill and follows safe usage patterns.
  • [DATA_EXFILTRATION]: The skill communicates with noiz.ai (the vendor's domain) to perform voice design and synthesis tasks. It correctly manages the NOIZ_API_KEY by reading from standard environment variables or a local config file (~/.noiz_api_key), adhering to security best practices for secret management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 05:30 AM
Security Audit — agent-trust-hub — chat-with-anyone