elevenlabs-voice-changer

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an installation script on the vendor's official GitHub repository (inference-sh/skills) to set up the necessary CLI environment.
  • [COMMAND_EXECUTION]: The skill utilizes the 'infsh' CLI tool to execute voice transformation tasks, which is the core intended functionality.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection through external audio URLs. Evidence: 1. Ingestion points: the 'audio' input parameter in SKILL.md. 2. Boundary markers: absent. 3. Capability inventory: access to the 'infsh' CLI tool. 4. Sanitization: absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 12:27 PM