transcribe

Pass

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill processes media files locally, ensuring user data privacy by avoiding cloud-based transcription services.- [EXTERNAL_DOWNLOADS]: The skill automatically downloads Whisper models from the Hugging Face Hub (specifically the mlx-community organization). This is necessary for the skill's primary function and targets a reputable source.- [PROMPT_INJECTION]: Processes untrusted media files which could theoretically contain indirect prompt injection content in the resulting transcript. The agent should handle the output as data rather than instructions to mitigate this inherent risk.- [COMMAND_EXECUTION]: Employs dynamic context injection in the documentation to check for the presence of uv and ffmpeg. These checks are static, do not accept user arguments, and are used solely for environment diagnostics.
Audit Metadata
Risk Level
SAFE
Analyzed
May 5, 2026, 01:35 AM