videoagent-audio-studio
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill relies on the
@elevenlabs/mcppackage, which is a standard utility from a well-known service provider, and installs it via the npm registry. - [COMMAND_EXECUTION]: The skill executes local shell scripts and Node.js commands to manage the audio generation workflow, including starting an MCP server and running a CLI tool for proxy communication.
- [DATA_EXFILTRATION]: The skill transmits user-provided text and prompts to a remote proxy hosted at
audiomind-proxy.vercel.app(managed by the vendor, pexoai) to perform audio generation. The proxy service also tracks basic usage telemetry (generation counts and error rates) using a remote Upstash Redis instance. - [INDIRECT_PROMPT_INJECTION]: As the skill processes user-supplied text to generate audio, it possesses a standard attack surface for indirect prompt injection. A malicious prompt could theoretically attempt to manipulate the audio generation parameters (e.g., duration or model selection), though the impact is restricted to the skill's specific audio output capabilities.
- Ingestion points: User-supplied text via MCP tool arguments or CLI flags.
- Boundary markers: None observed in the interpolation of prompts into API requests.
- Capability inventory: MCP tool invocation, CLI execution, local file system writes (audio files), and network requests to generation APIs.
- Sanitization: Input is passed directly to the remote API without significant filtering or escaping.
Audit Metadata