synthesis-voice-profiler

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection by processing external data such as URLs and local files as writing samples without explicit boundary protection.
  • Ingestion points: The skill fetches URLs and reads local files provided by the user as writing samples in Step 1 of the process.
  • Boundary markers: The instructions do not specify any delimiters or warnings to the agent to ignore instructions contained within the processed samples.
  • Capability inventory: The skill utilizes file reading and network fetching capabilities to gather writing samples.
  • Sanitization: No sanitization or filtering process is described for the content retrieved from external sources before analysis.
  • [DATA_EXFILTRATION]: The skill provides a mechanism to read local files and fetch content from external URLs based on user input. This capability could be used to expose sensitive information if an attacker provides paths to private configuration or credential files instead of the intended writing samples.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 09:44 AM
Security Audit — agent-trust-hub — synthesis-voice-profiler