openai-whisper
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses the Homebrew package manager to install the
openai-whispertool. This is a standard installation method for developer tools and targets an official package for a known utility. - [COMMAND_EXECUTION]: The skill provides usage examples for the
whispercommand-line interface. These commands are executed locally to process audio files and do not involve suspicious network activity or elevated privileges. - [PROMPT_INJECTION]: The skill processes external audio data (e.g.,
.mp3,.m4a) which serves as an ingestion point for untrusted content. While this presents a surface for indirect prompt injection if the transcribed text contains malicious instructions, the skill uses a local processing model from a trusted vendor, which is a standard utility function with no specific malicious patterns detected.
Audit Metadata