text-to-speech
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill retrieves voice metadata and generated audio content from HeyGen's official API and resource domains, including api.heygen.com, resource.heygen.ai, and resource2.heygen.ai. These are recognized infrastructure for the service provider.
- [DATA_EXFILTRATION]: To authenticate requests, the skill utilizes the HEYGEN_API_KEY environment variable. This is a secure method for managing secrets, and the credential is only transmitted to the vendor's authorized endpoints for identity verification.
- [COMMAND_EXECUTION]: The documentation includes standard curl command examples for testing API connectivity. These commands are benign, intended for developer reference, and do not involve unauthorized system modifications or privilege escalation.
Audit Metadata