audio
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents methods for ingesting untrusted external audio data from URLs and microphone input, which represents a potential attack surface for indirect prompt injection if the resulting data is later processed by an LLM without proper sanitization.
- Ingestion points: The skill utilizes
decodeAudioData(inaudio.md) to load remote audio files andAudioRecorder(inrecording.md) to capture microphone input. - Boundary markers: There are no explicit boundary markers or instructions to ignore embedded signals within the provided code patterns.
- Capability inventory: The skill provides capabilities for writing to the local filesystem via
AudioRecorderand performing network read operations viaStreamerNodeanddecodeAudioData. - Sanitization: No specific audio data sanitization or validation logic is included in the provided patterns.
- [EXTERNAL_DOWNLOADS]: The documentation includes examples that demonstrate fetching audio assets from remote URLs.
- Evidence:
audio.mdcontainsdecodeAudioData('https://example.com/audio.mp3')andplayback.mdincludesstreamer.initialize('https://example.com/stream.m3u8'). These are noted as standard placeholders for developer implementation. - [COMMAND_EXECUTION]: The skill provides instructions for package installation and code generation using common CLI tools.
- Evidence:
worklets.mdrecommends runningnpm install react-native-workletsand describes usingnpx rn-audioapi-custom-node-generator create -o ./to scaffold custom native nodes. - [DYNAMIC_EXECUTION]: The skill leverages Audio Worklets to execute custom JavaScript logic on specialized high-performance runtimes.
- Evidence: Use of
WorkletNode,WorkletSourceNode, andWorkletProcessingNodeinworklets.mdto run procedural synthesis and real-time effects.
Audit Metadata