ai-voice-bots
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements voice-processing pipelines (Pipecat, LiveKit) that ingest untrusted user speech transcribed via STT services. This data is interpolated into LLM prompts to handle conversation logic and execute tools such as order lookups or human transfers. The provided examples lack explicit boundary delimiters (e.g., XML tags or clear separators) to prevent the LLM from following malicious instructions contained within the user's speech.
- Ingestion points: STT transcript frames processed in
references/pipecat-patterns.mdandreferences/livekit-agents-patterns.md. - Boundary markers: Generally absent or limited to standard system prompt instructions in code samples.
- Capability inventory: Support for tool calling (
lookup_order,transfer_to_human), network requests to external providers, and file writing for audio caching. - Sanitization: The skill includes utility processors for PII redaction and profanity filtering, but these do not address adversarial prompt injection attempts.
- [EXTERNAL_DOWNLOADS]: The skill references and provides implementation patterns for several well-known and trusted external services, including Anthropic, OpenAI, Deepgram, Cartesia, and ElevenLabs. These integrations are essential for the skill's primary purpose and use established API protocols.
- [COMMAND_EXECUTION]: The skill includes Python utility scripts (
scripts/voice_latency_audit.py,scripts/call_quality_scorer.py) intended to be executed via the command line for auditing and quality scoring. These scripts process local log files and do not exhibit dangerous execution patterns.
Audit Metadata