speech-to-text

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the infsh command-line tool to interface with remote transcription models (e.g., ElevenLabs Scribe, Whisper V3). This is the intended behavior for utilizing the vendor's platform.\n- [EXTERNAL_DOWNLOADS]: Links to the official vendor repository on GitHub (inference-sh/skills) are provided for CLI installation and documentation. These are trusted vendor resources.\n- [DATA_EXFILTRATION]: Audio files are transmitted via URL to the inference.sh cloud infrastructure for processing. This is a core feature of the service and is documented as such.\n- [PROMPT_INJECTION]: As the skill processes external audio content into text, there is an inherent surface for indirect prompt injection if the transcribed text contains instructions that an agent might erroneously follow in subsequent steps. This is a common risk for all transcription-based skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 11:55 PM