vowel-react
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of legitimate documentation and boilerplate for integrating the vowel.to voice SDK into React-based frontend projects.
- [EXTERNAL_DOWNLOADS]: The skill references the installation of '@vowel.to/client' and the well-known '@ricky0123/vad-web' utility from public registries. These are appropriate dependencies for the described functionality.
- [DATA_EXFILTRATION]: No evidence of unauthorized data access or exfiltration was detected. The skill uses standard environment variable placeholders and emphasizes using public API key prefixes for client-safe configuration.
- [PROMPT_INJECTION]: The system instruction templates provided for the voice agent are safety-oriented. They include explicit directives for the agent to use registered application actions and avoid direct DOM manipulation, which reduces the risk of unintended behavior.
Audit Metadata