elevenlabs-tts

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references external installation instructions hosted on GitHub for the belt CLI utility from the inference-sh repository.- [COMMAND_EXECUTION]: The skill utilizes the belt command-line tool to execute remote applications, manage user authentication, and perform audio synthesis.- [INDIRECT_PROMPT_INJECTION]: The skill presents an injection surface by processing user-supplied text for synthesis.
  • Ingestion points: The text field within the JSON input for the belt app run command.
  • Boundary markers: No explicit boundary markers or instruction-ignore wrappers are used for the user input.
  • Capability inventory: The skill is restricted to using the belt tool via Bash.
  • Sanitization: No sanitization or filtering of the input text is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:19 PM
Security Audit — agent-trust-hub — elevenlabs-tts