tts
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches audio data from remote sources as part of its core functionality.
- Evidence:
scripts/tts.pydownloads reference audio files from default vendor URLs onnoiz.aior well-known cloud storage atstorage.googleapis.comif no local file is provided. - Evidence: Both
scripts/tts.pyandscripts/render_timeline.pysupport downloading reference audio from arbitrary user-supplied URLs via CLI arguments or JSON configuration. - [COMMAND_EXECUTION]: The skill relies on several external command-line tools to process and play audio.
- Evidence: It executes
ffmpegandffprobefor tasks such as format conversion, duration matching, and timeline mixing inscripts/render_timeline.py. - Evidence: It calls the
kokoro-ttsbinary for local offline synthesis when the Kokoro backend is selected. - Evidence: It attempts to use system utilities like
afplay,aplay, orpaplayto provide immediate audio playback for the user. - Note: These subprocess calls use list-based argument passing, which prevents shell command injection.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input data that could potentially contain malicious instructions intended for the AI agent.
- Ingestion points: Untrusted data enters via text files (
--text-file,--input), SRT subtitle files (--srt), and JSON voice-map configurations (--voice-map). - Boundary markers: No delimiters or specific 'ignore instructions' warnings are applied to the ingested content.
- Capability inventory: The skill has the capability to perform network requests (uploading text to Noiz API) and execute local commands (ffmpeg, kokoro-tts).
- Sanitization: No sanitization or instruction filtering is performed on the input text before it is sent to the synthesis backends.
Audit Metadata