NYC

text-to-speech

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE] (SAFE): No malicious patterns detected. The script performs standard text-to-speech operations.
  • [Data Exposure & Exfiltration] (LOW): The script includes functionality to read local text files and write audio files to disk. These capabilities are necessary for the skill's primary purpose and do not involve unauthorized network access.
  • [Indirect Prompt Injection] (LOW): The skill ingests untrusted data from user input and local files.
  • Ingestion points: scripts/text_to_speech.py accepts text strings and file paths via CLI arguments.
  • Boundary markers: Absent.
  • Capability inventory: File reading, audio file writing, and audio playback.
  • Sanitization: No sanitization of input text is performed before processing by the TTS engine.
  • Assessment: Low risk as the output is restricted to audio synthesis and does not influence agent logic or system state.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:31 PM