voice-interface-builder
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- SAFE (SAFE): The skill contains no executable scripts or binary files. Its primary purpose is to provide documentation and code templates for the Web Speech API within a developer workflow.
- Indirect Prompt Injection (LOW): The skill facilitates the creation of systems that ingest untrusted voice data which could be used for indirect prompt injection. Evidence Chain: 1. Ingestion points: Transcripts generated from the Web Speech API (referenced in README.md). 2. Boundary markers: None present in the documentation. 3. Capability inventory: According to manifest.yaml, the skill has capabilities to modify files and create artifacts. 4. Sanitization: No sanitization or validation logic is defined in the provided snippets.
Audit Metadata