skills/vesely/skills/wispr/Gen Agent Trust Hub

wispr

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the macOS open utility to interact with the Wispr Flow application via URI schemes. This is a standard method for application control on macOS.\n- [INDIRECT_PROMPT_INJECTION]: The switch-mic functionality provides a surface for command injection by interpolating unvalidated user input into a shell execution context.\n
  • Ingestion points: The <PREFIX> parameter in SKILL.md used for microphone identification.\n
  • Boundary markers: The URL template uses double quotes, but there are no instructions to the agent to escape shell-sensitive characters (e.g., backticks, semicolons, or dollar signs) before substitution.\n
  • Capability inventory: Shell execution capability via the open command.\n
  • Sanitization: No sanitization, validation, or escaping logic is defined for the interpolated user input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:21 PM
Security Audit — agent-trust-hub — wispr