edge-tts

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill generates shell commands using placeholders for user-provided text and filenames. This constitutes a potential indirect prompt injection surface.
  • Ingestion points: {msg} and {filename} in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: Shell command execution via uvx edge-tts in SKILL.md.
  • Sanitization: Not explicitly defined in the skill instructions.
  • [EXTERNAL_DOWNLOADS]: The skill relies on uvx to download and run the edge-tts package from the Python Package Index (PyPI) at runtime, which is standard behavior for this tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 10:39 AM
Security Audit — agent-trust-hub — edge-tts