NYC

voice-interface-builder

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • SAFE (SAFE): The skill contains no executable scripts or binary files. Its primary purpose is to provide documentation and code templates for the Web Speech API within a developer workflow.
  • Indirect Prompt Injection (LOW): The skill facilitates the creation of systems that ingest untrusted voice data which could be used for indirect prompt injection. Evidence Chain: 1. Ingestion points: Transcripts generated from the Web Speech API (referenced in README.md). 2. Boundary markers: None present in the documentation. 3. Capability inventory: According to manifest.yaml, the skill has capabilities to modify files and create artifacts. 4. Sanitization: No sanitization or validation logic is defined in the provided snippets.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:16 PM