say
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands and system utilities. SKILL.md runs a local script using bun. The gemini-say.ts script invokes afplay, ffmpeg, and nowplaying-cli using spawnSync to manage audio playback and system audio states.
- [INDIRECT_PROMPT_INJECTION]: The skill processes assistant messages which may contain content derived from untrusted external sources. 1. Ingestion points: Reads the 'last assistant message' for summarization. 2. Boundary markers: Lacks formal delimiters in the command string, relying on natural language constraints. 3. Capability inventory: Accesses shell execution and file writing. 4. Sanitization: Instructs the agent to output plain text without markdown or symbols.
- [CREDENTIALS_UNSAFE]: The script reads Google Cloud service account keys from ~/.config/gemini-say.env. This is standard for Vertex AI authentication in local tools.
- [EXTERNAL_DOWNLOADS]: The skill connects to well-known Google API endpoints (oauth2.googleapis.com and aiplatform.googleapis.com) to fetch tokens and synthesize speech.
Audit Metadata