skills/usevowel/skills/vowel-react/Gen Agent Trust Hub

vowel-react

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of legitimate documentation and boilerplate for integrating the vowel.to voice SDK into React-based frontend projects.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of '@vowel.to/client' and the well-known '@ricky0123/vad-web' utility from public registries. These are appropriate dependencies for the described functionality.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data access or exfiltration was detected. The skill uses standard environment variable placeholders and emphasizes using public API key prefixes for client-safe configuration.
  • [PROMPT_INJECTION]: The system instruction templates provided for the voice agent are safety-oriented. They include explicit directives for the agent to use registered application actions and avoid direct DOM manipulation, which reduces the risk of unintended behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 06:19 PM