text-to-speech
Pass
Audited by Gen Agent Trust Hub on Mar 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
infshCLI tool via theBash(infsh *)allowed tool to perform tasks like model listing and speech generation. - [PROMPT_INJECTION]: The skill has an indirect prompt injection surface. 1. Ingestion points: The
--inputJSON parameter ininfsh app runcommands (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Shell command execution viaBash(infsh *)(SKILL.md). 4. Sanitization: Absent. User-provided text passed to external TTS models could contain malicious instructions designed to influence the model's output or the agent's logic.
Audit Metadata