edge-tts
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill generates shell commands using placeholders for user-provided text and filenames. This constitutes a potential indirect prompt injection surface.
- Ingestion points:
{msg}and{filename}inSKILL.md. - Boundary markers: Absent.
- Capability inventory: Shell command execution via
uvx edge-ttsinSKILL.md. - Sanitization: Not explicitly defined in the skill instructions.
- [EXTERNAL_DOWNLOADS]: The skill relies on
uvxto download and run theedge-ttspackage from the Python Package Index (PyPI) at runtime, which is standard behavior for this tool.
Audit Metadata