descript

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements a 'verify by ear' requirement, ensuring a human reviews and approves all AI-driven edits and synthetic audio before publication.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes external transcript data.\n
  • Ingestion points: Processes transcript text from recordings in SKILL.md and references/the-words-framework.md.\n
  • Boundary markers: Does not employ technical delimiters for transcript data but provides clear instructional context for text-based editing.\n
  • Capability inventory: Can trigger Underlord actions via API/MCP and initiate publishing through WoopSocial (references/scope-and-connections.md).\n
  • Sanitization: Mitigated by mandatory human approval of the final audio output, preventing the silent execution of instructions that might be embedded in transcript text.\n- [SAFE]: The skill explicitly restricts voice cloning to the user's own voice with verified consent and strictly forbids cloning third parties or public figures.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 02:27 PM
Security Audit — agent-trust-hub — descript