openai-whisper

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses the Homebrew package manager to install the openai-whisper tool. This is a standard installation method for developer tools and targets an official package for a known utility.
  • [COMMAND_EXECUTION]: The skill provides usage examples for the whisper command-line interface. These commands are executed locally to process audio files and do not involve suspicious network activity or elevated privileges.
  • [PROMPT_INJECTION]: The skill processes external audio data (e.g., .mp3, .m4a) which serves as an ingestion point for untrusted content. While this presents a surface for indirect prompt injection if the transcribed text contains malicious instructions, the skill uses a local processing model from a trusted vendor, which is a standard utility function with no specific malicious patterns detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 08:43 PM
Security Audit — agent-trust-hub — openai-whisper