telnyx-voice-media-java

Pass

Audited by Gen Agent Trust Hub on Mar 12, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes data from external sources during call operations. * Ingestion points: The speak command's payload field and the transcription_text field in the callRecordingTranscriptionSaved webhook (SKILL.md). * Boundary markers: The provided examples do not demonstrate the use of delimiters or specific instructions to the model to ignore potential commands embedded in the transcriptions or payloads. * Capability inventory: The skill uses the Telnyx Java SDK to perform call control actions such as playing audio, speaking text, and managing recordings. * Sanitization: There is no evidence of sanitization or validation of the text-to-speech payloads or the transcribed call content before processing.
  • [EXTERNAL_DOWNLOADS]: The skill references the official Telnyx Java SDK repository on GitHub for installation instructions. This is a trusted vendor resource.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 12, 2026, 03:08 AM